You can use public-private key cryptography that the enemy cannot compromise unless they compromise the NSA (the private keys).
Deliberate introduction of hard to exploit 0days would be precisely how they would do it. All you need is one plant with commit access.
Note the date - 04. September 1999.