Alternately, it could just be that Certicom saw a means to profit off of an emerging standard by modifying it to support key escrow. It's not like key escrow in general was something that no had thought of before in 2005. If this was an NSA backdoor, why would the NSA reveal it publicly by having Certicom patent it? Not to mention that it this was a horribly unpopular algorithm long before any suspicion of it being a backdoor. If it was an NSA campaign to break public cryptography, it was a miserable failure long before Snowden ever hit the scene.