suppose NSA can easily generate SHA256 collisions,
There is a lot less reason to suppose that the NSA, or anyone else, can currently generate collisions on RIPEMD160(SHA256()) then can shortcut ECDSA.
I mean we already know how to compromise ECDSA in about 4 billion operations. It's "Just an engineering problem".