Look at some of these, lol:
1. Polar-KEM: the submitted code contains functions that recover the shared secret using only the public key and ciphertext. A complete public-key-only break.
2. CEDRUS+C: a real signature forgery after collecting 1,000 signatures; around three CPU minutes.
3. MasterCube: trivial hash collisions.
4. Aigis-Enc+: ciphertext rejection writes to the wrong buffer, directly breaking IND-CCA security.
5. AFS-KEX: the supposedly ephemeral key is generated once and stored as long-term state, destroying forward secrecy.