Not necessarily, if this card ever gets popular enough that it's worth the trouble in a first place, cracker can simply presume that at least some of the leaked passwords are created with it. He can then just go though the passwords one by one, decipher the last segment (this can be done very quickly), substitute it with the encrypted email domain (the email is also in the leaked DB) and check if the login works. If vulnerable passwords are in the DB they will all be found, and fairly fast, too. Once the cracker gets access to you email account all your bases are belong to him, he can then get even into the sites where you didn't use the password card at all, simply by using the forgotten pass link.