科技史宇宙Civiliverse

Disaster

Chernobyl

切尔诺贝利

A test run to verify a safety feature became the worst accident in the history of nuclear power.

View in the atlas

On 26 April 1986 the fourth unit of the Chernobyl nuclear plant in Soviet Ukraine ran out of control during a turbine coast-down test; a steam explosion lifted the thousand-tonne upper biological shield, the graphite moderator burned for ten days, and radioactive material spread on the winds across half of Europe. The official attribution underwent a major revision: in 1986 operator violations were blamed, while in 1992 an international expert group placed the primary cause in the RBMK design—its positive void coefficient and the flaw in its control rods.

Date
1986
Place
Pripyat, Ukrainian SSR, Soviet Union
Civilisation
Western
Fields
Energy & Power, Medicine & Life

The safety we relied upon rested on questions no one was willing to ask.

—— Summarized from the thesis of Valery Legasov's post-accident tapes (1988)
Unit four at Chernobyl in 2006, with the shelter built over it after the accident and the security perimeter in front. Inside the fence it remains a closed zone.
Unit four at Chernobyl in 2006, with the shelter built over it after the accident and the security perimeter in front. Inside the fence it remains a closed zone.Carl Montgomery, CC BY 2.0, via Wikimedia Commons source

History

The purpose of the test was not in itself absurd: if outside power fails, what feeds the main pumps during the tens of seconds before the diesel generators come up? The engineering idea was to use the coasting turbine as a generator. On the night of 25 April 1986 unit four reduced power for the test; a dispatcher's request delayed it by hours, so a different shift took it over, and xenon poisoning dropped power unexpectedly low. To continue, the operators withdrew too many control rods and disabled several protection signals. At 1:23 a.m. the test began: coolant flow fell and steam voids grew—and the RBMK at low power has a positive void coefficient, so more voids mean more reactivity and rising power. The shift chief pressed AZ-5 to scram, but the rods of this design carry graphite at their lower ends, which on first insertion displaces water and locally adds reactivity: a fatal shove. Within seconds power surged, a steam explosion lifted the shield, and the graphite caught fire. What followed was helicopters dropping boron and lead, firefighters and "liquidators" working in extreme fields, the evacuation of Pripyat some thirty-six hours later, and the "sarcophagus" completed in November. The radioactive plume was first detected by monitoring stations in Sweden, after which the Soviet Union acknowledged the accident. In 2016 the New Safe Confinement was moved into place over the old shelter.

Why it matters

The most durable lesson of Chernobyl lies in the revision of its attribution. In 1986 the IAEA's first report (INSAG-1) largely adopted the Soviet account and laid responsibility on operator violations; INSAG-7 in 1992 shifted that weight, finding the positive void coefficient and the graphite-tipped rods to be inherent design faults of which the operators were unaware—the button they pressed had been described to them as a scram. This is not an exculpation of individuals. By a foundational principle of safety engineering, a system that is safe only when people do not err is not safe. A further layer concerns information. The rod defect was recorded in earlier internal documents and never conveyed to operators; the silence after the accident then delayed protective measures in neighbouring countries. Technological risk is never only a physical quantity; it is simultaneously an institutional question of who knows what and who is permitted to say it. Set beside DDT and the ozone hole, the nuclear accident shows that what differs among such cases is not the degree of danger but the speed of institutional response.

Connections

Consequences1

Sources

Open questionswell attested