For the sake of historical accuracy, the NIST backdoor argument goes back to 1999 and Michael Scott [1]. I don't really buy it: if the NIST curves can't be trusted purely by association, then I find it very hard to trust the other curves as well.

[1] https://groups.google.com/forum/#!msg/sci.crypt/mFMukSsORmI/...

