# UUPSUpgradeable Vulnerability Post-mortem

**URL:** <https://forum.openzeppelin.com/t/uupsupgradeable-vulnerability-post-mortem/15680>\
**Category:** Announcements\
**Created:** [September 16, 2021, 5:29pm UTC](https://forum.openzeppelin.com/t/uupsupgradeable-vulnerability-post-mortem/15680 "2021-09-16T17:29:26Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![gnarvaja](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.openzeppelin.com/gnarvaja/32/21458_2.png) [@gnarvaja](https://forum.openzeppelin.com/u/gnarvaja)\
**Post date:** [September 27, 2021, 8:27pm UTC](https://forum.openzeppelin.com/t/uupsupgradeable-vulnerability-post-mortem/15680/5 "2021-09-27T20:27:35Z")

</div>

If you are thinking about major changes, perhaps you may want to consider adding protection on who can run `initialize`.  
IMHO, leaving the possibility of having contracts that might be initialized by anyone even when they are implementation contracts it's a potential threat. Let's say someone initializes and hijacks an implementation contract deployed by a trusted address, and with social hacking methods tries to make people interact with that contract instead of the Proxy.

Following the same patch you did for 4.3.2, you can add an immutable variable registering the contract's creator address.

```auto
 address private immutable __self = address(this);                                                                    
+address private immutable __creator = msg.sender; 

```

And then put a validation on `initialize` function that has to be called either from the proxy or from `__creator`.

---

_[View the full topic](https://forum.openzeppelin.com/t/uupsupgradeable-vulnerability-post-mortem/15680)._
