I don't really understand why they use HMAC-SHA256. Why do many schemes decide to do this needlessly when they can use SHA3 or Blake2b?
SHA3 and Blake2* use different constructions that don't have these flaws, thus they don't require HMACs for their needs.