Nostr's choice of curve is still somewhat perplexing to me.
Discussion
Why? It's the Bitcoin curve, very dear to everybody's heart.
Satoshi curve > Google curve > NIST curve
(secp256k1 > ed25519 > p521, et al)
Oh, did I say NIST curve? My bad, I meant NSA curve... *cough* #[4]
it's not considered a 'safe curve', recommended for diffie hellmann by some. that was not considered to be a problem for bitcoin as bitcoin used ecdsa only.

"as long as you use libsecp256k1 and don't try to rewrite it at home, this doesn't pose a security problem."
guess that's ok then.