> the new hash function is going to be broken eventually
SHA-2 will not be broken as easily as SHA-1. This seems to be a common misconception in this thread.
Wikipedia: "Since 2005, SHA-1 has not been considered secure against well-funded opponents".
This was 10 years after its introduction (1995) and 15 years ago. We had 15 friggin' years and we're finally switching git and bittorrent around. It took 2017-2005=12 years to get from first serious signs of issues to https://shattered.io.
SHA-2 is now 19 years old and the "uh oh, better switch before it's too late" recommendation has not come yet. It's withstanding the test of time better and there haven't been 12 years to mature any weaknesses. The theoretically known attacks for SHA-2 are fairly insignificant.
Since SHA-2 had a similar construction to SHA-1 (Merkle-Dåmgard), NIST figured they better launch the SHA-3 competition at the first sign of trouble and picked something with a very different operating principle. For now, however, it's still fine. Thomas Pornin put this a bit better than I can: https://security.stackexchange.com/a/21116/10863
As for "what happens if/when it will be broken": we could make BitTorrentv2 another multi-crypto soup like with TLS, but then you open up a can of downgrade attacks, potential null ciphers or other such tricks simply due to increased complexity, and you still can't switch that quickly because everyone needs to take manual action in changing configuration files. Much better if we can instead do apt upgrade and let the software take care of making security decisions rather than those who install the software. (Remember that SSL was designed in 1994, when LiveScript/JavaScript didn't even exist yet, DES was state of the art, and we wrote books with algorithms because cryptography was ammunition. Having multiple options for strong/weak ciphers was not yet a crazy idea.)