If anything, the use of curve secp256k1 seems to hint that it was not the NSA. They would have more likely to have used suite b standard ecdsa over curve secp25r1/nistp256 at the time.
While the idea that Bitcoin came from the State is intriguing, it’s really more likely to have come from the cypherpunk community.
Interesting, I haven't researched the secp256k1. Something to look into...
reply