With regards specifically to SHA256, I’m not worried. If it became too easy to solve Bitcoin block nonces, we can soft-fork in additional difficulty requirements. Breaking SHA256 means anyone can be a 51% attacker without actually having the hash. So un-upgraded nodes would be vulnerable. But Bitcoin would survive.