logo

Upgradeable Proxy Contract Security Best Practices

ID: 69209bd3-70f3-5cdb-ae54-bbeae38adfa9

STIX ID: report--69209bd3-70f3-5cdb-ae54-bbeae38adfa9

Feed Name: CertiK Blog

Threat Score
70/100

Date Published: 2022-11-18

Date Updated: 2026-06-11

...
...

This report explains upgradeable smart contract proxy patterns (Transparent, UUPS, Beacon), catalogs common security failures (admin key compromise, uninitialized implementation contracts, storage slot collisions, and untrusted delegatecall/call) with real-world incidents (PAID Network, Parity Multisig, Audius, Pickle Finance, etc.), and provides operational and development best practices to mitigate risks such as initializing implementations, using EIP-1967 storage slots, segregating admin and governance roles, employing multisig for admin keys, and avoiding dangerous constructs like selfdestruct and delegatecall to untrusted addresses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.