Follow the chronology from 01:23:04 to around 01:24: turbogenerator, pumps, steam, AZ-5, excursion signals, recording gaps, and rupture of Reactor 4.

Check it out!

The turbogenerator test at Chernobyl Reactor 4 formally began at 01:23:04 on April 26, 1986, when the stop valves of turbogenerator 8 were closed. About 36 seconds later, at 01:23:40, the EPS-5 signal associated with AZ-5 was recorded. At 01:23:43, the systems were already indicating rapid power growth.

This article reconstructs the interval between the start of the test and destruction of the reactor. Events from the preceding hours — delay imposed by the electrical grid, power drop, xenon, low ORM, and rod configuration — appear only as entry conditions.

The answer cannot be reduced to “an electrical test went wrong.” The test interfered with power to the main pumps and therefore connected the turbine, electrical generation, coolant flow, pressure, steam formation, and reactivity. It is also not technically rigorous to state that a single event alone explains the final seconds.

The available records contain gaps and have different sampling cycles. Therefore, the chronology distinguishes three levels: recorded events, interpretations supported by models, and points that remain controversial. The purpose is to show how a vulnerable condition rapidly evolved into loss of control, process failures, and structural rupture.

What Was Scheduled for the Night at Reactor 4?

On the night of April 25–26, 1986, Reactor 4 was to be shut down for scheduled maintenance. This created an opportunity to repeat a test that had been performed previously but without satisfactory results.

The test concerned electrical power for the cooling-water circulation pumps. In a nuclear plant, removal of heat from the core is a critical function. Even when the reactor is shut down, the fuel continues producing decay heat, which must be removed in a controlled manner.

The problem the test sought to assess was: if electrical power were lost, could the turbine, still rotating by inertia, temporarily provide enough energy to keep essential pumps running until the emergency diesel generators started?

This interval was short but technically relevant. The diesel generators did not instantly assume full load. There was a transition. And in critical systems, transitions are always sensitive moments.

What Was the Turbine Test?

The turbine test, also called a rundown test in some sources, sought to verify the behavior of the turbine-generator set during deceleration.

In normal operation, steam produced by the reactor drove the turbine, and the turbine drove the generator. During the test, the idea was to cut steam supply to the turbine and observe whether residual mechanical energy from rotation would still be sufficient for a few seconds to power selected pumps.

In simple terms:

  1. reactor power would be reduced;
  2. steam supply to the turbine would be interrupted;
  3. the turbine would continue rotating by inertia;
  4. the coupled generator would still produce power for a short period;
  5. that power would supply circulation pumps;
  6. the emergency diesel generators would then take over.

The test therefore was not an experiment without purpose. It addressed a critical-infrastructure question: how can vital functions be maintained during the transition between loss of one power source and entry of an emergency source?

The same reasoning applies to substations, data centers, hospitals, operation centers, telecommunications, SCADA systems, and critical industrial installations.

Why Did This Test Matter for Safety?

The test sought to verify a power transition: after loss of the main supply, kinetic energy from the decelerating turbine-generator should temporarily sustain selected loads until the diesel generators started. The issue was legitimate because circulation functions cannot disappear during transfer between power sources.

However, classifying the test as essentially electrical concealed its interfaces. Reduced voltage and frequency changed the performance of pumps connected to the turbogenerator; pump behavior influenced flow, pressure, and steam formation; and these variables interacted with core physics.

An integrated test must define initial conditions, participating systems, unavailable functions, operating limits, stop criteria, recording instruments, and who is responsible for the decision to proceed. When an assumption is no longer true, the program must be formally reassessed — not simply continued with local adaptations.

Commissioning and Technical Acceptance

Integrated tests verify transitions between sources, response times, interlocks, priority loads, and combined system behavior using measurable criteria and traceable evidence.

Learn about Commissioning and Technical Acceptance

The Delay Caused by Grid Demand

Power reduction began on April 25 but was interrupted at the request of the electrical-system controller, which needed the unit to continue generating. The postponement prolonged operation at intermediate power and transferred execution of the test to another shift.

The delay was not merely a scheduling change. It altered the reactor’s thermal and neutron history, changed the state of the teams, and moved the activity away from the originally planned timing conditions. When the reduction resumed, the system was no longer in the same state as at the start of the program.

Shift handover also needed to transfer assumptions, changes, unavailable conditions, points of attention, and authority to stop the test. In critical systems, operational information is part of system configuration just as much as equipment and control logic.

Requirements, Evidence, and Acceptance-Criteria Management

Changes in assumptions, postponements, and exceptions need to be recorded, assessed, and approved, maintaining traceability among test objective, actual conditions, and the decision to proceed.

Learn about Requirements Management

Power Reduction and the First Critical Condition

When the test resumed, the reactor was supposed to be stabilized within an appropriate power range. However, during the reduction, power fell far below the intended level.

This drop placed Reactor 4 in a difficult condition. An RBMK operating at low power, especially under certain xenon-poisoning conditions and irregular power distribution, required delicate control.

INSAG-7, the International Atomic Energy Agency report that revised the initial conclusions about the accident, highlights that operating the RBMK at low power, under certain instrumentation and control conditions, imposed significant difficulties on operators. At low power, visibility into the spatial distribution of power in the core was limited, and the operator had to deal with a large, sensitive system that was partially decoupled across different core regions.

This point is essential: Reactor 4 was not a simple piece of equipment responding uniformly. It was a complex physical system with a large core, spatial neutron distribution, local power variations, water, steam, graphite, control rods, and reactivity effects.

The Role of Xenon in Reactor 4

After a power reduction, one phenomenon that affects nuclear-reactor behavior is the buildup of xenon-135.

Xenon-135 is a fission product that absorbs neutrons. Because neutrons are needed to sustain the chain reaction, xenon acts as a reactor “poison,” reducing available reactivity.

In practice, this means that after a power drop, the reactor may have difficulty recovering power. To compensate, operators may be led to withdraw control rods, increasing available reactivity.

This is what made the situation even more delicate. The attempt to recover and stabilize power occurred under a condition in which the operational reactivity margin was reduced.

The problem was not merely the presence of xenon. It was the combination of xenon, low power, rod configuration, RBMK characteristics, core power distribution, and the decision to proceed with the test.

Withdrawal of the Control Rods

Control rods exist to absorb neutrons and regulate the nuclear reaction. When inserted into the core, they tend to reduce reactivity. When withdrawn, they leave more neutrons available to sustain or increase the reaction.

During the attempt to recover power after the drop, many rods were withdrawn. This reduced the margin available for rapid control and placed the reactor in a vulnerable configuration.

INSAG-7 gives special attention to this point when discussing the operational reactivity margin, known as ORM. The report notes that the safety significance of this margin was not fully understood by operators. It was not merely an operating-reference value; it directly affected reactor behavior, including reactivity coefficients.

In other words, rod position was not merely a control detail. It changed the reactor’s own sensitivity to disturbances.

The Actual Start of the Test

The test began at 01:23:04 with closure of the stop valves of turbogenerator 8. From that moment, the set began to decelerate and the pumps connected to the generator under rundown received progressively lower voltage and frequency.

The records indicate that during approximately the first 30 seconds, the monitored parameters remained within the range expected for that condition. This is important: destruction did not occur at the same instant the valves were closed, and simply starting the test does not by itself explain the transient.

Why Was the Test Not Merely Electrical?

Deceleration of the turbogenerator changed the supply to four main pumps. The electrical change affected pump speed; speed influenced circulation; circulation affected temperature, pressure, and steam fraction; and steam fraction affected reactivity through the positive void coefficient.

Therefore, the true object of the test was an integrated system, not merely the generator. Inadequate classification reduced the attention devoted to interfaces among electrical power, hydraulics, automation, protection, and core physics.

Chronology of the Final Seconds

  1. 01:23:04: closure of turbogenerator 8 valves and formal start of the test.
  2. 01:23:40: EPS-5 signal recorded, associated with AZ-5 activation, and start of movement of the protection and control rods.
  3. 01:23:43: signals of rapid power growth and activation of period and overpower protections; the recorded value exceeded 530 MWt.
  4. 01:23:46 to 01:23:47: shutdown of the pump pairs under rundown, abrupt flow changes, and increased pressure and level in the steam separators.
  5. 01:23:49: signal of increased pressure in the reactor space, consistent with channel rupture, loss of the 48 V supply, and actuator failures.
  6. Around 01:24: the operating record mentions severe shocks and rods stopping before reaching the lower limits.

SCADA Systems

Historians, sequence of events, time synchronization, and data retention make it possible to reconstruct transients and distinguish command, actuation, process response, and subsequent failure.

Learn about SCADA Systems

What Do the Records Not Show Directly?

DREG recorded hundreds of signals but did not continuously store central parameters such as power, reactivity, and flow in each channel. Of the 211 rods, only a small sample of positions was recorded. Other calculations, such as those from PRIZMA, had cycles lasting several minutes and were interrupted during SKALA restarts.

The oscillography system installed for the test had good resolution for electrical variables but was not perfectly synchronized with reactor records. The chronology can be approximated with good confidence for discrete events, but the core’s spatial evolution depends on later models.

Digital Supervision and Control Systems

A supervision architecture must display critical states, margins, data quality, and unavailability, correlating electrical, mechanical, and process variables on a common timeline.

Learn about the SDSC solution

What Remains Controversial?

Later analyses agree that low ORM, the strong void effect, and rod design made the core vulnerable. The controversy lies in the relative weight of the mechanisms during the seconds immediately before AZ-5.

One interpretation attributes the start of the excursion mainly to increased steam during pump deceleration. Another considers the positive insertion effect of the rods, after the shutdown command, the decisive factor in the abrupt rise. INSAG-7 concludes that the combination of both mechanisms was sufficient to produce the severe transient observed.

The more rigorous formulation is that AZ-5 did not by itself create the vulnerable condition, but the design of the control rods could worsen the transient precisely when the safety function should have dominated it.

From AZ-5 to the Final Seconds

After the shutdown signal, the rods began moving but did not complete their travel. The rapid increase in power intensified steam generation and pressure; channels began to fail; and the physical damage itself compromised rod movement and actuator availability.

The progression moved from a reactivity transient to multiple process and structural failures. Pressure generated by the simultaneous rupture of several channels exceeded the capacity of local confinement and displaced upper reactor structures. The upper cover, described in technical sources as a structure on the order of 2,000 tonnes, lost its barrier function.

The central point is not the isolated image of a “lid being thrown,” but the cascading loss of barriers: fuel, pressure channels, cooling circuit, core structures, confinement, and control systems ceased to perform their functions within a few seconds.

The Moment of the Explosion

The moment of the explosion marked the transition from reactor instability to a nuclear, environmental, operational, political, and human crisis.

From that point onward, the control room was no longer dealing merely with a test that had gone out of control. Reactor 4 had been destroyed. Essential physical systems no longer existed as containment barriers. Radioactive materials were released. Fires started. Local teams, firefighters, operators, and authorities faced an unprecedented situation.

It is important to note that the destruction of Reactor 4 was not the consequence of a single isolated act. It resulted from a chain of events:

  1. test planned during a scheduled shutdown;
  2. operational delay due to electricity demand;
  3. shift change and alteration of the test context;
  4. excessive power drop;
  5. xenon poisoning;
  6. withdrawal of control rods;
  7. reduction of operational reactivity margin;
  8. start of the test under a vulnerable condition;
  9. change in cooling flow;
  10. increase in steam;
  11. positive void coefficient;
  12. activation of AZ-5;
  13. undesired initial rod effect;
  14. abrupt power rise;
  15. structural rupture and explosion.

This sequence is more important than any simplistic explanation.

What Does the Night of the Accident Reveal About Critical Systems?

The sequence shows that major failures rarely belong to a single discipline. The test originated as an electrical activity but depended on pumps, hydraulics, automation, instrumentation, protection, operations, and core physics. The absence of an integrated view allowed each part to be treated separately while risk emerged from the interfaces.

The first lesson is that initial conditions are part of the test. A procedure validated for a given power level, configuration, system availability, and team does not automatically remain valid after hours of delay, a shift change, and changes in process state.

The second is that technical margins need to be visible and linked to decisions. It is not enough to calculate a variable such as ORM; its meaning must be presented, the value updated at an appropriate rate, and configurations incompatible with safety automatically prevented.

The third is that an emergency function must be verified end to end. The command, power supply, actuators, movement of elements, response time, and effect produced on the process must be demonstrated under normal and degraded conditions.

The fourth is that high-resolution data are part of safety. Without synchronization, quality, coverage, and adequate retention, the team loses situational awareness during the event and the ability to learn afterward.

Test Governance and Independent Review

A test that interferes with safety systems must have a single technical owner for the whole activity, independent review, a responsibility matrix, risk analysis, stop criteria, and formal approval of changes. Production or dispatch pressure cannot silently change safety assumptions.

Independent review must also challenge oversimplified classifications. Calling the test “electrical” did not eliminate its nuclear consequences; similarly, in substations, data centers, or industrial installations, a change in telecommunications, software, or auxiliary power can affect protection and operational continuity.

Owner’s Engineering

Independent engineering integrates disciplines, reviews assumptions, verifies interfaces, and ensures that schedule, operational, and performance decisions do not compromise critical project requirements.

Learn about Owner’s Engineering

The Parallel with Current Critical Infrastructure

In a substation, transfer between power sources may involve auxiliary services, protection, telecommunications, synchronization, and supervision. In a data center, it may involve UPS systems, generators, cooling, automation, and electrical distribution. In both cases, the installation is ready only when transitions and combined failures have been tested and documented.

The principle is the same: individually approved equipment does not guarantee system behavior. Safety and availability depend on interfaces, actual operating conditions, and the ability to recognize when an activity no longer satisfies the assumptions that justified its execution.

Conclusion

Between 01:23:04 and approximately 01:24, Reactor 4 progressed from the start of a rundown test to loss of essential control, cooling, and structural-barrier functions. The speed of the progression shows why the final seconds cannot be explained solely by an isolated decision in the control room.

The test interfered with a coupled system: turbogenerator, pumps, circulation, pressure, steam, reactivity, rods, and protection. The initial condition already combined low ORM, unfavorable spatial distribution, xenon, and strong void sensitivity. When AZ-5 was activated, the safety function depended on rod geometry capable of producing an undesired initial response under certain configurations.

The records confirm the sequence of the main events, but they do not continuously measure all variables required to attribute the first power increase to a single mechanism. The most consistent interpretation is systemic: steam formation and the positive insertion effect acted on a vulnerable core, producing a rapid transient followed by multiple failures.

The next chapter extends the analysis beyond the final seconds: Chernobyl: Design Failure, Political Pressure, or Governance Failure?. There, the question moves beyond “what happened” to “why did so many technical and institutional barriers fail together?”

Technical References

[1] INTERNATIONAL ATOMIC ENERGY AGENCY. The Chernobyl Accident: Updating of INSAG-1. Safety Series No. 75-INSAG-7. Vienna: IAEA, 1992.

[2] SHTEYNBERG, N. A. et al. Causes and circumstances of the accident at Unit 4 of the Chernobyl Nuclear Power Plant. In: INTERNATIONAL ATOMIC ENERGY AGENCY. INSAG-7, Annex I. Vienna: IAEA, 1992.

[3] ABAGYAN, A. A. et al. Causes and circumstances of the accident and measures to improve the safety of plants with RBMK reactors. In: INTERNATIONAL ATOMIC ENERGY AGENCY. INSAG-7, Annex II. Vienna: IAEA, 1992.

[4] UNITED STATES NUCLEAR REGULATORY COMMISSION. Report on the Accident at the Chernobyl Nuclear Power Station. NUREG-1250. Washington, DC: NRC, 1987.

[5] UNITED STATES NUCLEAR REGULATORY COMMISSION. Implications of the Accident at Chernobyl for Safety Regulation. NUREG-1251. Washington, DC: NRC, 1987.

[6] CHERNOBYL NUCLEAR POWER PLANT. Sequence of Events: Chernobyl Accident. Technical chronology consolidated from operating records.

[7] INTERNATIONAL NUCLEAR SAFETY ADVISORY GROUP. Safety Culture. INSAG-4. Vienna: IAEA, 1991.

[8] INTERNATIONAL ATOMIC ENERGY AGENCY. RBMK Reactors. Technical description and safety characteristics of graphite-moderated reactors.

[9] MUELLNER, Nikolaus. Three Decades after Chernobyl: Technical and Institutional Lessons. Vienna: University of Natural Resources and Life Sciences.

[10] WORLD NUCLEAR ASSOCIATION. RBMK Reactors and Chernobyl. Technical overview and subsequent safety modifications.

Frequently Asked Questions
What Was Being Tested at Reactor 4?

The test verified whether residual energy from the decelerating turbogenerator could temporarily power selected pumps until the diesel generators started.

When Did the Test Actually Begin?

The formal start occurred at 01:23:04, with closure of the stop valves of turbogenerator 8.

When Was AZ-5 Activated?

The EPS-5 system signal associated with AZ-5 was recorded at 01:23:40, initiating movement of the protection and control rods.

Was Power Already Increasing Before AZ-5?

There is technical controversy. The available records do not allow all core parameters to be reconstructed with sufficient resolution, and later analyses assign different weights to steam formation and the positive insertion effect.

Why Was the Test Not Merely Electrical?

Because deceleration of the turbogenerator changed power to the main pumps and therefore interacted with flow, temperature, pressure, steam formation, and core reactivity.

What Was the Role of the Positive Void Coefficient?

The increase in steam fraction reduced neutron absorption by water and could increase reactivity, creating positive feedback in an already vulnerable condition.

Why Do the Records Not Allow a Perfect Reconstruction?

The systems had different sampling cycles, did not record all relevant parameters, and experienced interruptions, while the electrical records were not perfectly synchronized with reactor data.

Did the Accident Result from a Single Cause?

No. Destruction of Reactor 4 resulted from the interaction of operating conditions, RBMK physical characteristics, rod design, low ORM, the test, supervision, and governance failures.

Additional Technical Materials

Solutions

Engineering Services

Chernobyl Learning Journey