A proposal of efficient certificateless signature scheme is presented to insecure against public key replacement attack. It is shown that an adversary who replaces the public key of the original signer can forge valid proxy delegations for the corresponding proxy signer without knowledge of the signer's pri- vate key, and can even forge valid proxy signatures. To thwart this attack, an improved scheme is further proposed, which is not only more securer but also avoids the problems of the original scheme.