Eleven Safeguards, One Wrong Valve, and a $95 Million Explosion at Shell

A large industrial petrochemical plant at dusk, showing cracking furnaces and distillation towers with steam venting. The scene has an ominous, heavy atmosphere — orange glow from the facility against a grey sky. Foreground shows industrial piping and valves. Documentary photorealistic style, muted industrial palette. No text, no people.

A worker clicked the wrong valve.

Six minutes later, a furnace exploded.

That is the shortest possible version of what happened at Shell Polymers Monaca in Pennsylvania on June 4, 2025. But a newly released investigation by the U.S. Chemical Safety and Hazard Investigation Board makes clear that reducing the accident to human error would miss almost everything important about it.

The CSB found that Shell had identified the possibility of a potentially fatal explosion, had 11 administrative controls that it believed would prevent such an event, and had access to engineered protections that could have made the mistake substantially harder to commit.

The 11 controls failed. Furnace 5 exploded. Shell estimated the property damage at $95 million.

Remarkably, nobody was injured.

The Setup: A First-Time Task, a Confusing Screen

The Monaca complex, which began operating in 2022, converts ethane into ethylene for plastics production. Its ethane cracking unit contains seven furnaces.

Furnace 5 had been taken offline so workers could clean its coke trap. None of the facility’s seven coke traps had previously been cleaned since operations began. When the work was finished, Shell began returning Furnace 5 to operation.

That required reopening large motor-operated valves separating the furnace from the downstream process.

The engineer assigned to open one of those valves had never performed the task before.

The computer interface did not make matters easier.

Three valves appeared on the same safety-system logic screen. Their identifiers differed only by their final digit: 511, 512 and 513. The furnace-side valve was displayed near the top of the screen; the tower-side valve the engineer intended to open was near the bottom.

After the engineer entered the system’s debug mode, the screen refreshed and returned to the top.

The engineer inadvertently commanded the wrong valve open.

The Alarm That Told Nobody Anything

Even then, the system had another opportunity to reveal the mistake. An alarm activated when the unexpected valve began moving. But its description was essentially identical to that of the expected valve, again differing principally by the last digit. Because operators knew a valve was supposed to be opening, the alarm was acknowledged without corrective action.

Eventually the intended valve was opened as well.

That created a path allowing flammable cracked gas to flow backward into Furnace 5, where the pilots were still burning.

At 2:21 p.m., the gas ignited.

The explosion severely damaged the furnace and released an estimated 5,100 pounds of ethylene and combustion products. Fifteen employees were evacuated. A contractor became trapped in an elevator beside Furnace 5 and had to be rescued. Other workers were also in the vicinity.

There was no exclusion zone around the furnace because Shell did not consider the operation a startup activity or abnormal situation.

They Knew. They Chose Paperwork Anyway.

The more consequential finding, however, concerns what Shell knew before the explosion.

According to the CSB, Shell’s process hazard analysis had already identified cracked-gas backflow as a potentially fatal explosion scenario.

Shell nevertheless relied on 11 administrative controls — things dependent upon policies, procedures, alarms, training and workers correctly carrying them out — rather than an engineered control capable of physically or automatically preventing the dangerous valve configuration.

The report becomes particularly uncomfortable when it examines Shell’s earlier risk analysis.

Shell had identified two administrative safeguards against an explosion: operator response to a high-methane alarm and a startup procedure.

Neither was functioning as assumed on the day of the accident.

The alarm was suppressed, and the startup procedure considered during the hazard analysis wasn’t being used.

The Protections Were Right There

Shell’s hazard-analysis team had previously concluded that adding engineering controls would be “grossly disproportional to the risk reduction” they would provide. CSB reached a rather different conclusion, finding that Shell had actively chosen to rely solely upon administrative controls to prevent a potentially fatal explosion.

Perhaps most strikingly, engineered protections were not some technology waiting to be invented.

Shell licensed the furnace technology from Linde, whose original design incorporated engineered safeguards. One involved a sequenced-key interlock intended to prevent an incorrect valve opening. Another was designed to automatically close the furnace-side valve when conditions associated with backflow were detected.

Those protections were not implemented for the double-isolated configuration involved in the accident.

Nineteen Times It Worked. Once It Didn’t.

Meanwhile, Shell had successfully performed essentially the same isolation-and-return operation 19 times before the explosion.

Nineteen successes apparently demonstrated that the procedure could work.

The twentieth demonstrated what happened when it didn’t.

$26,480 in Fines. $95 Million in Damage.

Afterward, Shell changed the system. Operations personnel can now manipulate the valves from a local control panel rather than requiring a process-control engineer to override the safety system. New logic prevents the tower-side valve from opening if the furnace-side valve has mistakenly been opened, and Shell developed a new step-by-step operating procedure.

OSHA also issued three citations stemming from the accident. They addressed shortcomings in the process hazard analysis, inadequate consideration of human factors and the absence of clear operating procedures for returning the valves to normal operation.

The proposed penalty was $26,480.

The estimated property damage was $95 million.

The CSB’s report therefore provides a useful distinction between the person who made the final mistake and the system that determined what would happen when someone inevitably made one.

A worker selected the wrong valve.

But before that click ever occurred, the explosion hazard had been identified, administrative safeguards had been chosen, engineered protections had gone unused in this configuration, alarms could be suppressed, an inexperienced engineer could manipulate nearly identical controls, and the interface provided precious little assistance in distinguishing one valve from another.

Human error explains the click.

It does not explain the system that allowed one wrong click to become a $95 million explosion.


Discover more from Bureaucracy Times

Subscribe to get the latest posts sent to your email.