It seems there's enough evidence that NSA inserted the secret values in one standard already:
http://en.wikipedia.org/wiki/Dual_EC_DRBG