Perfect forward secrecy doesn't work that well when NSA motto is - store everything now decrypt later. If they intercept the ephemeral key exchange now they can decrypt the message 10 or 50 years later.
Something tells me that by the end of the century only the one-time pads will still be holding their secrets.
Diffie Hellman doesn’t ever send the key over the wire, that’s the point. There is nothing to decrypt in the packets that tells you the key both sides derived.
Unless they break ECDHE, it doesn’t matter if RSA gets popped.