Jinsan, hashcash’s flaw is that it requires the browser to interpret a md5 routine written in JavaScript to codify a result. At first sight, this would require a browser to interpret the code. However, this is not true, as the only requirement is to “interpret” an md5 routine, any spammer that has a, say, perl script with an md5 routine can generate the correct answer and send the form automatically. I don’t know if you’ve received any spam using HashCash, but it has been reported elsewhere (look in the WP-HashCash main page).
Best regards,