A kleptographic vulnerability (one which cannot be exploited without breaking a cryptographically strong problem) is entirely different from the plain "ECC believed strong but actually weak" situation. Once the latter vulnerability is known anyone could break it, but the former vulnerability is strong even if the theoretical basis for the backdoor is discovered.
It's the same fundamental difference between building a computational-theoretical hard algorithm and security-by-obscurity. The NSA is not dumb enough to bet on their trick remaining obscure - that stuff inevitably gets rediscovered, whether it's 5 years or 20 years. But it's easy to precompute E in the DUAL_EC_DRBN algorithm, while it's cryptographically strong to try and reverse it after the fact. Trapdoor functions work like one-way secure hashes (eg SHA) by design - easy in forwards, computationally infeasible (as a design goal) in reverse.
The patent on the concept of using that as a backdoor (although not in that exact phrasing) was filed in Jan 2005 [1] (years before the selection of the NIST curves in FIPS 186-3) and it's reasonable to believe the NSA would know of the existence of the backdoor since the filing at a minimum - if not before. It was published for public comment in 2007 [1] but didn't gain much publicity until granted in 2013(!) [2] after Snowden had gotten the disclosure train rolling.
If you have a specific page/paragraph reference you'd like to cite: please do, it's a topic I feel strongly about since the consequences of a compromised kleptographic backdoor could be rather extreme for anyone who uses those curves.