One thing instantly comes to mind: SHA-3
As revealed, previously NSA has made NIST to insert their backdoored PRNGs into the standards etc.
NIST organized the competition to find the function to be called SHA-3 and one must wonder if Keccak won and was titled the SHA-3 because of some useful weaknesses NSA discovered in it.