I don't know specifically about secp256r1, but in general, I think there were already a lot of suspicions and most people were wary of any ECC curves NIST or NSA had chosen by 2008 when Bitcoin was developed. [1]
In a purported email [2] (reasonably well attested to) from Satoshi Nakamato, he claimed
> I didn't find anything to recommend a curve type so I just... picked one.
[1] https://web.archive.org/web/20140621062515/http://archive.wi...