2^166 ~= give a separate quantum computer that does as many QOPS as the the most powerful supercomputer does FLOPS to each human who has ever lived and have each of them run for a thousand times the age of the universe.
Symmetric and one-way functions are provably secure, within those characteristics that they define. Notably, they are not designed with "until the end of the universe" promise (and the only proven "until the end of the universe" encryption anyway is a proper one-time pad (or disk) encryption). The reason that certain hashing and encryption algorithms have been broken are due to both compromises inherent in design goals (notably, AES have been simplified from the reference encryption Rjindael to ease up hardware acceleration) and the march of technology simply rolling with faster chips. Quantum computing can speedup this process a bit (a quadratic speedup in most cases), but not enough to outbeat these types of encryption.
Not a big deal by itself.
But not sha256, no. I think you'd almost have to design it to be vulnerable, if you want that.
IMHO this design decision was a great call.
EDIT: I'm amazed that for 12 hours nobody could point to that well-known fact. NH crowd really knows little about cryptocurrencies.
How secure is 256 bit security? https://www.youtube.com/watch?v=S9JGmA5_unY