Here's a register article from 2007 about page table permissions being problematic. If you look around a bit, there were a ton of security researchers who talked about the problem. It seems to have been a bit of an open secret that such a thing must exist -- they just hadn't found it yet.
https://www.theregister.co.uk/2007/06/28/core_2_duo_errata/
The scariest part is that many of the best security minds work for various intelligence agencies. They very likely have known about such things for a very long time.
Meltdown strikes me as an almost perfect vulnerability. It affects almost everyone. It is undetectable until exploited and once exploited, it immediately goes away until the next time. It's easy to keep secret. Most importantly, it's a one-way vulnerability. Keep your secure systems from running untrusted code and there's zero risk. Since this is standard protocol anyway for those systems, you don't have the risk of someone running across a code patch somewhere.
The only potential downside is that the juiciest targets also aren't running untrusted code (though most foreign affairs workers probably run untrusted code). The big point of interest here is information symmetry. In most cases, giving others secret information is bad. In this case, both the best and worse case situations work out well for the USA. If nobody else knows, they get free info. If everyone else does know, then everyone gets perfect information about everything. This favors the most powerful country. They can eliminate the unknowns (the only real danger). In contrast, knowing you are going to be crushed does nothing if you can't hide your own hand either. So, the best case is very good and the worst case is still acceptable.