The difficulties with fast constant-time point multiplication seem to be precisely the type problem the NSA might know of earlier. I.e. it's possible they contrived the standards to something they knew people could easily get wrong. Not a reason not to use them, just food for thought.