Federal Probe Finds Preventable Control Failure Behind Shell’s $95 Million Explosion

A highly automated plant had identified a potentially fatal gas-backflow hazard, yet its principal defenses were 11 administrative controls dependent on people following procedures. The U.S. Chemical Safety and Hazard Investigation Board’s final investigation, released September 16, 2026, found that this arrangement allowed an unintended valve operation to cause an explosion at Shell Polymers Monaca in Pennsylvania and approximately $95 million in property damage.

https://youtu.be/KYNDk23KbzY

The June 4, 2025, incident began while Furnace 5 was being returned to service after its coke trap had been cleaned. A process-control engineer inadvertently opened two motor-operated isolation valves simultaneously. That created a route for flammable cracked gas to flow backward from downstream equipment, through the quench system and into the furnace firebox.

Approximately six minutes after the valves opened, the accumulated gas encountered lit pilot flames and ignited. The explosion ruptured the firebox wall and was followed by a fire. Fifteen employees evacuated, but no one was killed or seriously injured. An estimated 5,100 pounds of ethylene and combustion products were released. Furnace 5 required extensive repairs and remained out of service for roughly seven months.

Why the finding goes beyond operator error

The immediate valve selections were only one part of the failure. Investigators found that the engineer assigned to the task had never performed it before and had limited process knowledge. More importantly, the control and safety architecture allowed an incorrect selection to establish a hazardous flow path into a furnace containing active pilot flames.

Shell’s process hazard analyses had already identified cracked-gas backflow as a scenario capable of causing a fatal incident. Even so, the plant relied on 11 administrative controls to manage the risk during the relevant transition out of double isolation. Such controls can include procedures, training, supervision and required checks. They are important, but their effectiveness ultimately depends on people interpreting information correctly and performing each step as intended.

An engineered safeguard occupies a stronger position in the hierarchy of controls because it can physically or logically prevent an unsafe state rather than merely instructing someone to avoid it. The furnace technology licensor had supplied controls capable of preventing backflow, according to the investigation, but Shell had not configured them for the operating transition involved in the incident.

That distinction is central to why the explosion was preventable. The known hazard did not lack a technical solution. The available protection simply did not cover every relevant operating mode, leaving a safety-critical gap during a nonroutine transition.

The interface was part of the safety system

The human-machine interface also made the relevant valves difficult to distinguish. Three nearly identical valves appeared on one logic screen, and their identification tags differed mainly in the final digit. In a complex process plant, that is not merely a usability problem. Screen organization, labeling and command feedback affect whether an operator can reliably understand the plant state and anticipate the result of an action.

Automation does not remove human factors from industrial operations. It relocates them to displays, alarm logic, permissions, interlocks and the handling of unusual operating states. A control room may be sophisticated while still placing too much safety responsibility on a worker’s ability to discriminate between similar symbols during an unfamiliar task.

The six-minute interval between the valve opening and ignition further illustrates why protection must extend across the complete sequence. A command can appear routine at the interface while its physical consequences develop elsewhere in connected equipment. Engineered logic designed around process conditions can interrupt that progression before combustible material reaches an ignition source.

Recommendations remain open

The CSB issued two recommendations to Shell Polymers Monaca. One calls for reviewing hazard analyses to identify potentially catastrophic scenarios controlled only by administrative measures, then applying inherently safer designs or engineered safeguards where appropriate. The other calls for an engineered control, developed with input from the technology licensor and recognized industry practices, that prevents cracked-gas backflow into a furnace during all operating modes.

The CSB is an independent federal investigative agency and does not issue citations or fines. Its recommendations depend on recipients responding and demonstrating acceptable corrective action. Both Shell recommendations are currently listed as open, awaiting a response or the evaluation and approval of a response.

The unresolved test is therefore broader than repairing Furnace 5. It is whether a hazard already recognized as potentially fatal will be blocked by configured engineering in every operating mode, rather than managed primarily through another layer of instructions.

More aerospace and engineering stories, right in your MSN feed.
Follow AMI on MSN

By Thomas Caldwell — AMI’s senior editor for mechanical and mobility engineering, covering vehicle electronics, systems integration, electrification, chassis systems, propulsion, and safety policy.

Leave a Reply

Discover more from Aerospace and Mechanical Insider

Subscribe now to keep reading and get access to the full archive.

Continue reading