Understand the chain that led to the Reactor 4 explosion: power drop, xenon, ORM, positive void coefficient, control rods, AZ-5, the test, and governance failures.
Check it out!
The Chernobyl accident was not caused by a single error, a single button, or a single reactor characteristic. The destruction of Reactor 4 resulted from the convergence of a degraded operating state, vulnerabilities in the RBMK design, a test conducted after its initial conditions had been lost, insufficient protections and information, and governance failures that allowed the sequence to continue.
The causal answer can be summarized as follows: power fell to a very low range; the core changed state and became more difficult to control; recovery consumed operational reactivity margin; the test changed flow, steam generation, and thermal-hydraulic conditions; the positive void coefficient amplified the response; AZ-5 initiated rod insertion from an unfavorable configuration; and the initial effect associated with the rod design worsened a condition that already had little tolerance. The rapid power increase produced intense steam generation, overpressure, channel rupture, and structural destruction.
Chernobyl did not explode like an atomic bomb. The uncontrolled nuclear energy release generated the heat that drove the sequence, but the initial destruction was predominantly thermal-hydraulic and mechanical: steam, pressure, rupture, and displacement of structures.
This article serves as the causal synthesis of the cluster. Each mechanism is presented only to the level needed to understand its position in the chain. Specialized chapters examine RBMK operation, reactor architecture, the power drop, xenon, ORM, the void coefficient, the control rods, AZ-5, and the chronology of the final seconds.
Why Is There No Single Cause for Chernobyl?
In complex systems, the immediate cause of a failure is not necessarily its complete explanation. Reactor 4 ruptured because power and pressure increased rapidly. However, that response became possible only because several preceding barriers had already been degraded.
A proper analysis must separate at least five levels:
- immediate physical cause: rapid steam generation, overpressure, and structural rupture;
- immediate nuclear mechanism: abrupt increase in reactivity and power;
- enabling conditions: low power, unfavorable spatial distribution, reduced ORM, steam, and rod positions;
- operational decisions: continuing after the reactor state changed and conducting the test outside planned conditions;
- systemic causes: vulnerable design, poorly translated limits, insufficient information, poor communication, and governance unable to interrupt the chain.
Reducing Chernobyl to “human error” erases the physical vulnerabilities later corrected in RBMK reactors. Reducing it to a “design defect” is also incomplete, because the sequence depended on the operating state built over the preceding hours and on decisions that kept the test going after its assumptions had been lost.
The RBMK Had Characteristics That Required Rigorous Control
The RBMK-1000 was a channel-type reactor moderated by graphite and cooled by boiling light water. Graphite slowed neutrons and maintained favorable conditions for fission. Water removed heat, produced steam, and also absorbed some neutrons.
This separation between moderator and coolant had an important consequence: when some liquid water turned into steam, neutron absorption by water decreased while graphite continued moderating. Under certain core states, the result could be an increase in reactivity.
The effect was neither constant nor uniform. It depended on power, fuel, absorbers, spatial distribution, flow, pressure, temperature, steam fraction, rod positions, and ORM. Therefore, merely saying that “the RBMK had a positive void coefficient” does not by itself explain the accident; it is necessary to understand the specific state in which this feedback came to dominate.
The large core could also exhibit very different radial and axial distributions at the same total power. A global megawatt indicator alone did not show how the reaction was distributed across reactor regions.
The Turbine Test Had a Legitimate Objective but Crossed Multiple Disciplines
The test sought to verify whether residual energy from a slowing turbine-generator could keep certain pumps powered during the interval between loss of the main supply and startup of the emergency diesel generators.
At first glance, it was an electrical test. In practice, it crossed generation, auxiliary power, pump drives, coolant circulation, steam formation, automation, protection, and core physics. The administrative boundary of the test did not correspond to the real boundary of risk.
This is a central point: when an activity changes auxiliary systems connected to the main process, its impact must be assessed across the complete system. The fact that the objective involved the turbine and electricity did not make the nuclear core indifferent to the test.
The Delay Changed the Initial Conditions of the Test
The power reduction began on April 25, 1986, but was interrupted at the request of the electrical system so the unit could continue generating. The reactor remained for hours in an intermediate condition before the reduction resumed at night.
The delay had simultaneous effects:
- it changed the core’s thermal and neutron history;
- it transferred the final stage to another shift;
- it prolonged a condition affecting iodine and xenon;
- it moved the test away from the originally intended scenario;
- it created a need to revalidate assumptions, team, limits, and system availability.
The delay caused by electrical dispatch is a documented fact. Claims about personal or political pressure behind each decision require caution and should not replace the technical records. The governance failure lies in allowing a significant change in scenario to be treated as simple continuation of the original plan.
Requirements, Evidence, and Acceptance-Criteria Management
Critical tests need traceable assumptions, limits, interruption criteria, responsible parties, and evidence that each condition was verified before execution.
The Power Drop Created a New Core State
At around 00:28, during resumption of the power reduction and transfer between automatic-control ranges, power fell to approximately 30 MWt. The available records do not establish a single immediate cause for this drop.
The technically decisive point is what happened next: the test had been planned for a different condition, but the team attempted to recover the reactor and continue. Power was raised and stabilized around 200 MWt, still below the originally intended range.
Recovering power did not mean recovering margins, spatial distribution, or the test’s initial conditions. The installation once again produced a certain global output, but the internal state of the core was different.
Xenon Made Recovery More Difficult but Does Not Alone Explain the Initial Drop
Xenon-135 is a strong neutron absorber. It is formed mainly by the decay of iodine-135. After a power reduction, neutron flux decreases and existing xenon is consumed more slowly, while accumulated iodine continues producing new xenon.
This phenomenon acts as memory of the power history. The core does not respond only to the instantaneous value shown on the panel; it carries the effects of the preceding hours.
Technical analysis must distinguish two statements:
- there is not sufficient basis to treat xenon as the direct and exclusive cause of the drop to 30 MWt;
- xenon was important in explaining why later recovery required additional rod withdrawal and why ORM decreased.
By compensating for poisoning, the team managed to raise power but consumed effective control capability.
ORM Showed That the Reactor Had Lost Margin
ORM, or operational reactivity margin, was not a simple visual count of rods. It was a calculated quantity expressed in equivalent rods that represented the remaining effective capability of the control system given the actual neutron-field distribution.
Later reconstructions produced different estimates for the final moments — approximately 1.9 or 6 to 8 equivalent rods, depending on the data and models used. The disagreement does not change the operational conclusion: the values were below the 15-rod limit associated with the need for shutdown.
Low ORM had three relevant consequences:
- there was little reserve to compensate for new disturbances;
- many rods were in positions that made the initial effect of the old design relevant;
- the overall core configuration became more sensitive to steam and the spatial distribution of power.
The margin was not available to the team as a continuous, rapid, clearly integrated decision variable. Calculation depended on the computer system and could arrive late relative to operational changes.
Digital Supervision and Control Systems
Calculated variables, spatial states, alarms, and interlocks need to be presented clearly, up to date, and at a rate compatible with process dynamics.
Pumps, Flow, and Steam Connected the Test to the Core
The circulation pumps were not external accessories to the process. They determined flow, heat removal, inlet temperature, pressure, and steam generation in the channels.
Before the test, pump and flow configurations were changed. When the turbine-generator began coastdown, the power supply to the pumps associated with the rundown also changed. The problem cannot be summarized as “not enough water” or as an isolated mechanical pump failure.
The relevant condition was the joint evolution of flow, pressure, temperature, and steam fraction. In an RBMK with positive void feedback and little control margin, increasing steam could reinforce power growth:
more steam → less absorption by water → more reactivity → more power → more heat → more steam
This feedback did not act in isolation. Its importance depended on the state built up over the preceding hours.
The Test Began at 01:23:04
At 01:23:04, closure of the turbine-generator valves marked the formal start of the test. From that point, turbine speed began to decrease and electrical and hydraulic variables associated with coastdown started to change.
The available records have different sampling cycles and synchronization. Therefore, reconstruction of the final seconds requires distinguishing:
- directly recorded events;
- values reconstructed by models;
- inferences about phenomena not measured directly;
- interpretations that remain debated.
The documentation does not support a simplistic narrative in which every variable remained stable until AZ-5, nor an equally absolute narrative in which the reactor was already inevitably doomed before the command. The state was vulnerable; the relative importance of mechanisms in the seconds immediately before and after AZ-5 requires careful analysis.
SCADA Systems
Historians, trends, data quality, and sequence of events make it possible to recognize progressive degradation and reconstruct decisions on a reliable time basis.
AZ-5 Was a Shutdown Command, Not an Isolated Cause
At 01:23:40, the EPS-5/AZ-5 signal was recorded. The command initiated insertion of the control and protection system rods.
The button did not “contain energy” or directly produce the explosion. It initiated a physical chain involving logic, power supply, actuators, rod movement, interaction with coolant, and the neutron response of the core.
In the old design, highly withdrawn rods left columns of water in regions of the channels. At the beginning of insertion, graphite displacers could replace this water before the absorber section dominated the effect. In an unfavorable spatial configuration, this introduced positive reactivity into part of the core.
AZ-5 must therefore be interpreted in two ways simultaneously:
- it was an attempt to shut down the reactor;
- its initial result was worsened by a known vulnerability in the rod design and by the state of the core.
Treating it as the sole cause erases the preceding hours of degradation. Treating it as an irrelevant detail ignores the physical mechanism that led to redesign of rods and protections in the remaining RBMK reactors.
Commissioning and Technical Acceptance
A safety function must be tested end to end, verifying command, power supply, actuation, timing, achieved position, and the actual process response.
The Final Seconds Combined Neutron and Thermal-Hydraulic Phenomena
The main documented milestones are:
- 01:23:04: formal start of the test;
- 01:23:40: EPS-5/AZ-5 signal and start of rod insertion;
- 01:23:43: signals associated with rapid power growth;
- 01:23:46–47: abrupt changes in flow, pressure, and level;
- 01:23:49: signs of actuator failures and conditions consistent with channel rupture;
- around 01:24: severe impacts, extensive damage, and interruption of rod movement.
Later models do not converge on a single peak-power value or reproduce every detail with equal precision. They do converge, however, on the importance of spatial distribution, void feedback, and rod geometry under the existing conditions.
The Destruction Was Not a Nuclear Detonation
The increase in reactivity rapidly raised the fission rate and heat generation. Transfer of this energy to the coolant produced intense vaporization, high pressure, channel rupture, and displacement of structures.
The conceptual sequence was:
reactivity → power → heat → steam → pressure → rupture
A later explosion was reported, and different interpretations discuss the role of hydrogen and other physicochemical phenomena. This does not change the main point: Chernobyl did not have the geometry, enrichment, or dynamics of a nuclear weapon.
Causal Matrix of the Accident
Immediate Physical Causes
- rapid steam generation;
- pressure rise;
- rupture of channels and structures;
- loss of reactor geometry and physical barriers.
Immediate Nuclear Mechanisms
- rapid increase in reactivity;
- localized and then global power growth;
- positive feedback associated with steam formation;
- initial effect of rod insertion under an unfavorable configuration.
Enabling Operating Conditions
- prolonged history of power reduction;
- drop to approximately 30 MWt;
- recovery only to about 200 MWt;
- xenon poisoning;
- withdrawal of many rods;
- ORM below the limit;
- unfavorable spatial distribution;
- altered hydraulic configuration;
- test started outside the original conditions.
Design Vulnerabilities
- significant positive void coefficient under certain states;
- rod geometry capable of producing an initial positive effect;
- conventional shutdown response too slow for rapid transients;
- insufficient indication of margins and spatial states;
- protections and interlocks unable to prevent certain configurations.
Governance Failures
- technical knowledge not rapidly converted into corrections and restrictions;
- incomplete communication among designers, manufacturers, operations, and regulators;
- interruption criteria insufficiently incorporated into the test;
- scenario changes without formal revalidation of assumptions;
- inadequate authority and independence to stop the activity;
- initial investigation excessively focused on operator actions.
Was Chernobyl Human Error?
There were relevant operational decisions: continuing after the power drop, recovering the reactor by withdrawing rods, keeping the test going under conditions different from those planned, and accepting reduced margins.
However, a safe installation cannot depend on every operator knowing vulnerabilities that were not adequately communicated, mentally calculating complex spatial states, or predicting that a shutdown function will produce an initial opposite effect in a configuration allowed by the system itself.
The more precise formulation is: human actions contributed to creating the dangerous state, but they encountered a vulnerable design and governance that failed to prevent convergence of the failures.
Were the Protections Simply Turned Off?
Some protection functions and systems were altered, blocked, or unavailable during preparation for the test. Isolation of the emergency core cooling system is frequently cited, but it should not be treated as the immediate physical cause of the explosion.
It is also incorrect to imagine that all important protections were switched off at once. The analysis must assess which function was active, which was blocked, why, at what time, and what actual causal relationship it had with the sequence.
The engineering lesson does not depend on exaggeration: reducing, bypassing, or making barriers unavailable while other margins degrade reduces the system’s overall tolerance.
What Changed in RBMK Reactors Confirms the Systemic Nature of the Problem
After the accident, the remaining RBMK reactors received modifications including:
- redesigned rods;
- larger absorber section;
- reduced conventional insertion time;
- additional fast-protection system;
- additional absorbers in the core;
- higher required ORM;
- fuel with higher enrichment;
- reduced void coefficient;
- numerical ORM indication;
- restrictions on blocking protection functions;
- new limits, procedures, and supervision systems;
- improvements in cooling, inspection, and auxiliary systems.
These changes demonstrate that real engineering vulnerabilities existed. They do not demonstrate that each retrofit individually corresponded to a single cause. The objective was to strengthen multiple layers of defense and prevent recurrence of the combination found in Reactor 4.
Owner’s Engineering
Independent review integrates design, operation, risks, interfaces, testing, and governance to prevent local decisions from compromising overall asset safety.
Lessons for Critical Systems and Infrastructure
Tests Need Verifiable Initial Conditions
A test plan must define power, configuration, margins, system availability, instruments, responsible parties, and interruption criteria. When an assumption changes, the test must be formally reassessed.
A Command Is Not Proven Performance
A command being sent does not prove the function was fulfilled. Power supply, logic, actuation, achieved position, response time, and actual effect on the process must be verified.
Margins Must Be Visible and Actionable
A critical variable should have a known method, quality, update rate, trend, alarms, and mandatory actions. A value calculated too late may fail as an operational barrier.
Interfaces Must Be Treated as Part of the System
Turbine, pumps, electrical supply, automation, process, and protection cannot be analyzed in silos when a change in one subsystem alters the behavior of the others.
Protection Must Work in Degraded States
A safety function must be validated under the states in which it will be most needed: low margin, unfavorable distribution, loss of power, unavailable sensors, configuration changes, and combined failures.
Technical Knowledge Must Become a Requirement
Identifying a vulnerability is not enough. It must generate a design change, operating restriction, training, documentation update, verification test, and acceptance evidence.
How to Continue the Chernobyl Learning Journey
For an overview of the event and its consequences, see the Chernobyl HUB.
To reconstruct the system before the accident, read Chernobyl before 1986, how the RBMK worked, and the architecture of components and systems.
To follow formation of the critical state, continue through the power drop, xenon-135, and the operational reactivity margin.
To understand the final mechanisms, see the positive void coefficient, the rods with graphite displacers, AZ-5, and the test chronology.
To conclude the systemic analysis, see human error, design failure, or governance failure and what changed in RBMK reactors after the accident.
Conclusion: The Explosion Was the Final Result of a Chain
Reactor 4 was not destroyed because one person pressed the wrong button. The installation reached its final seconds after hours of state changes, consumed margins, lost initial conditions, and insufficient barriers.
The power drop and xenon made recovery difficult. Rod withdrawal reduced ORM. The hydraulic configuration and steam formation encountered positive feedback. AZ-5 activated a function whose initial result depended on a vulnerable geometry. The rapid power increase produced heat, steam, pressure, and rupture.
The complete explanation includes physics, design, operation, information, safety culture, and governance. This is also the central lesson for any critical infrastructure: systemic accidents do not arise from a single error; they emerge when multiple defenses stop functioning as an integrated set.
Technical References
[1] INTERNATIONAL ATOMIC ENERGY AGENCY. The Chernobyl Accident: Updating of INSAG-1. Safety Series No. 75-INSAG-7. Vienna: IAEA, 1992.
[2] SHTEYNBERG, N. A. et al. Causes and circumstances of the accident at Unit 4 of the Chernobyl Nuclear Power Plant. In: INTERNATIONAL ATOMIC ENERGY AGENCY. INSAG-7, Annex I. Vienna: IAEA, 1992.
[3] ABAGYAN, A. A. et al. Causes and circumstances of the accident and measures to improve the safety of plants with RBMK reactors. In: INTERNATIONAL ATOMIC ENERGY AGENCY. INSAG-7, Annex II. Vienna: IAEA, 1992.
[4] UNITED STATES NUCLEAR REGULATORY COMMISSION. Report on the Accident at the Chernobyl Nuclear Power Station. NUREG-1250. Washington, DC: NRC, 1987.
[5] UNITED STATES NUCLEAR REGULATORY COMMISSION. Implications of the Accident at Chernobyl for Safety Regulation. NUREG-1251. Washington, DC: NRC, 1987.
[6] INTERNATIONAL NUCLEAR SAFETY ADVISORY GROUP. Safety Culture. INSAG-4. Vienna: IAEA, 1991.
[7] WORLD NUCLEAR ASSOCIATION. RBMK Reactors. London: WNA.
[8] CHERNOBYL NUCLEAR POWER PLANT. Sequence of events at Unit 4 on 25–26 April 1986.
[9] MUELLNER, Nikolaus. The Chernobyl Accident 1986. Vienna: University of Natural Resources and Life Sciences.
[10] OECD NUCLEAR ENERGY AGENCY. Chernobyl: Assessment of Radiological and Health Impacts. Paris: OECD/NEA.
Frequently Asked Questions
The explosion resulted from the combination of a degraded core condition, low ORM, positive void feedback, control-rod design, test conditions, operational decisions, and governance failures.
No. The uncontrolled power increase generated heat, steam, and pressure, producing structural rupture. There was no nuclear detonation like that of a weapon.
Xenon does not by itself explain the initial power drop or the explosion. It made power recovery more difficult and contributed to rod withdrawal and reduced ORM.
ORM represented the remaining effective control capability. Final estimates were below the operating limit, indicating little tolerance for new disturbances.
No. It amplified the response to steam formation in an already vulnerable state, interacting with power, flow, spatial distribution, rods, and ORM.
AZ-5 was an attempt to shut down the reactor. Rod insertion initially worsened the condition because of the old design and core configuration, but the command alone does not explain the entire chain.
Operational decisions contributed to the dangerous state, but the accident also involved design vulnerabilities, insufficient information, poor communication, and governance failures.
Control rods and protection systems were redesigned, required ORM was increased, the void coefficient was reduced, and instrumentation, procedures, supervision, cooling, and operational controls were improved.
Additional Technical Materials
Solutions
- Sistemas SCADA
- Digital Supervision and Control Systems
- Requirements, Evidence, and Acceptance-Criteria Management
Engineering Services
Chernobyl Learning Journey