> The idea of a hash function which outputs 256 bits having only 128 bits of preimage resistance is unprecedented.
But does the SHA-3 construction mean a collision attack will further enable a preimage attack? Most breaks in recent cryptographic hashes have been confined to collision attacks. Even MD5 (publicly) hasn't been shown to be vulnerable to a viable preimage attack.
It's worth remembering that just to count to 2^128 it'll take a 3 GHz core with a single cycle increment instruction, along with a billion of its friends, over 3 and a half trillion years.
Also, even if a 128 bit meet in the middle could be computed, it'd require an unfathomable amount of memory.