They use SHA-2-512 everywhere else already, presumably for post-quantum resistance. I guess it gives them a smaller cipher footprint? They use the same data type in their codebase for hashes? 512 bits is sufficiently future proof? Future use cases that haven't been thought of yet, that require a secure hash? 64 bytes isn't that much overhead?
But I'm really just guessing, I'm not sure what their reasons are.
I agree in principle - SHA-2-256 could be a reasonable hash function whilst maintaining the properties of a secure hash function - or less than that if collision resistance isn't needed.