Three Mile Island Didn't Fail From a Stuck Valve — It Failed From a Light Never Wired to Check It
Three Mile Island is remembered as a stuck valve and operators who got it wrong. The Kemeny Commission's own account says something narrower: the control room had no way to know the valve was open, because the panel light was never wired to the valve at all — only to the command sent to close it. And the exact failure mode that fooled them had already happened once, at another reactor of the same design, eighteen months earlier.
Chapters
- 0:00 4:00 a.m., March 28th, 1979
- 0:43 The part everyone leaves out
- 1:08 One light, one valve
- 1:37 Wired to the command, not the valve
- 2:08 A second gauge, misleading for a different reason
- 2:47 The system that worked correctly
- 3:21 Four and a half minutes in
- 3:42 Four warnings, explained away
- 4:13 "I had never seen that before"
- 4:43 The pumps start shaking
- 5:11 The top of the core
- 5:32 6:22 a.m.
- 6:12 Davis-Besse, September 1977
- 6:55 Eighteen months of filing, six days of warning
- 7:32 Half the core
- 7:50 What changed
- 8:26 Ten episodes, ten warnings
- 8:47 Next: still being verified
Transcript
Four in the morning, thirty-six seconds past the hour, March twenty-eighth, nineteen seventy-nine. Three Mile Island Unit Two, Pennsylvania — the worst accident in the history of commercial nuclear power in the United States is two seconds old. A set of water pumps stops. Eight seconds later, the reactor scrams — its control rods drop automatically, and the nuclear reaction stops. A valve at the top of the pressurizer opens, exactly as it was designed to. It's supposed to close again within seconds. It doesn't. It will stay open for more than two hours, and almost no one in the control room will know it.
The popular version of this story is short and mostly right: a valve stuck open, the operators made mistakes, part of the reactor core melted. What that version leaves out is the reason the mistakes happened. The operators in that control room weren't ignoring a warning. They were reading a panel that had been built, from the start, in a way that made it impossible for that warning to reach them.
The valve is called a pilot-operated relief valve, or PORV. It sits at the top of the pressurizer — the tank that keeps the reactor's cooling water under high pressure. When pressure spikes, the PORV is supposed to open, vent a little steam, and close again on its own. The control room had exactly one light to tell operators what that valve was doing. The question that matters is what that light was actually wired to.
It wasn't wired to the valve at all. There was no sensor on the valve itself that measured whether it was open or shut. The light was wired to the solenoid — the electromagnet that received the command to close the valve. Send the close signal, the solenoid loses power, the light goes dark, and the panel reads closed. That's true whether the valve actually closes or not. On this morning, it didn't. The panel had no way of ever finding out.
A second instrument was misleading them at the same time, for a related reason. As coolant escaped through the open valve, steam bubbles began forming inside the reactor core. That steam pushed water up into the pressurizer, so its level kept rising — even as the reactor was actively losing coolant. Operators were trained never to let the system go, in their term, solid — completely filled with water, a real hazard on its own. A rising pressurizer level read, to them, as too much water. It actually meant the opposite: the core was running out.
For the first two minutes, the plant's own safety systems handled this correctly, without a single decision from anyone in the room. Sensing the falling pressure, two emergency pumps switched on automatically — the high-pressure injection system. It poured about a thousand gallons a minute of replacement water straight into the reactor, doing exactly what it was built to do. The pressurizer level kept climbing anyway, because of the steam. That climbing number was about to override the one system that was actually working.
About four and a half minutes into the accident, operator Edward Frederick did exactly what his training told him to do. He shut off one of those high-pressure pumps and throttled the second down to a trickle — because the pressurizer level in front of him kept climbing. From that point on, the core began, for real, to uncover.
Six more signs followed in the next hour, and every one of them got explained away. A drain-pipe temperature that should have meant an open valve read as ordinary residual heat. A containment sump alarm at four eleven. A rupture disc bursting at four fifteen. An unusual neutron reading at four twenty, never connected to steam forming inside the core. Each explanation made sense on its own. None of them were checked against each other.
Around four forty-five, a technical supervisor named George Kunder arrived at the plant, called in by phone, expecting a routine turbine trip. What he found instead stopped him. Pressure in the reactor was low. The pressurizer level was pegged at the top of its scale. He later told the Commission he had never, in his experience, seen those two readings happen at once. Until that morning, the two had always moved together.
Shortly after five in the morning, all four reactor coolant pumps began shaking violently. It was the unmistakable sign of pumping a mixture of steam and water instead of water alone. Worried about damaging the pumps, operators shut two of them down at five fourteen, and the remaining two twenty-seven minutes after that. With no forced flow left, nothing was left pushing water past the top of the core.
By around six in the morning, radiation alarms inside the containment building signaled that fuel rod cladding had ruptured. The top of the core, uncovered and overheated, had reacted with steam and released hydrogen gas. Some of that hydrogen escaped straight out through the valve that was, still, wide open.
At six twenty-two, the leak finally stopped. Not because anyone diagnosed the stuck valve. A representative from the reactor's manufacturer happened to be on a phone call checking in on the plant. He asked a simple question: had the backup block valve been shut. No one in the room knew. Someone checked, and closed it. The open valve had been leaking for two hours and twenty-two minutes. And even then, the water the core needed wasn't reinjected for almost another hour. The official report calls that delay, in its own words, an unexplained reason.
None of this had to be a mystery. The same failure, in the same kind of reactor, had already happened once. On September twenty-fourth, nineteen seventy-seven, a relief valve stuck open at Davis-Besse, a nearly identical Babcock and Wilcox plant in Ohio. An engineer at the Tennessee Valley Authority, Carlyle Michelson, studied that event and wrote up the mechanism in detail. It predicted, specifically, that a small leak at the top of the pressurizer would make the water level rise while pressure fell. And that operators trained the normal way would very likely respond by cutting emergency cooling at exactly the wrong moment.
That study reached the Nuclear Regulatory Commission. And there it sat, for eighteen months, without becoming a design change, a training update, or a control room fix at any plant of that design. In March of nineteen seventy-nine, an NRC inspector named James Creswell grew frustrated enough to act. He flew to Washington on a Saturday, on his own dime, and took his concerns directly to two commissioners — outside the normal chain of command. That Saturday was March twenty-second. Three Mile Island began six days later.
By the time the core was finally recovered, roughly half of its fuel had melted. No death has ever been directly attributed to the radiation released that week. But public trust in nuclear power in the United States changed, permanently, in a matter of days.
The fix that followed wasn't a new valve design. It was a change in what control rooms were required to measure. Direct valve position indicators — not solenoid status — became standard equipment. Instruments that estimated actual water level inside the core, instead of inferring it from the pressurizer, became standard too. And warnings from one reactor of a given design started being treated differently. They became information every operator of that design needed — not paperwork that could sit in a file for a year and a half.
Ten episodes into this channel, that's ten different shapes of the same underlying problem. A warning that never existed. A warning that was overturned by the people who received it. And now, a warning that existed, that was correct, and that simply didn't travel fast enough to reach the room where it mattered.
The next case in this series is still being chosen. Its source will be verified before a single word of it is recorded, the same way every case in this channel has been.
Description and sources
At 4:00 a.m. on March 28th, 1979, a relief valve atop the pressurizer at Three Mile Island Unit 2, Pennsylvania, opened as designed to vent rising pressure. It was supposed to close again within seconds. It didn't — and stayed open for two hours and twenty-two minutes, draining coolant, while the control room believed it was shut.
The reason wasn't operator error in the usual sense. The panel's only indicator for that valve wasn't wired to a position sensor — there wasn't one. It was wired to the solenoid that received the close command: send the signal, the light goes dark, the panel reads closed, whether or not the valve actually moved. A second instrument was misleading operators for a related reason at the same time: as coolant escaped, steam forming in the core pushed water up into the pressurizer, so its level kept climbing even as the reactor lost coolant. Trained never to let the system go "solid," an operator throttled back emergency cooling about four and a half minutes in, based on a reading that meant the opposite of what his training said it meant.
Six more signals over the next two hours were each explained away individually — a drain-pipe temperature, a sump alarm, a burst rupture disc, an odd neutron count, violently vibrating coolant pumps, a technical supervisor startled by a combination of readings he'd never seen together. The leak was finally isolated at 6:22 a.m., not by diagnosis, but because a manufacturer's representative on a routine phone call asked whether a backup valve had been shut. By the time the core was recovered, roughly half its fuel had melted.
None of it had to be a mystery. The same failure, in a nearly identical reactor, had already happened at Davis-Besse, Ohio, in September 1977. An engineer at the Tennessee Valley Authority studied that event and predicted, in writing, the exact mechanism that would unfold at TMI. His study reached the Nuclear Regulatory Commission and sat there for eighteen months without becoming a design change, a training update, or a control room fix anywhere. An NRC inspector grew frustrated enough to fly to Washington on his own day off and take the case directly to two commissioners. That was six days before Three Mile Island began.
PRINT-READY, FROM THIS CHANNEL
The Failure Atlas, Vol. 01 — Tacoma Narrows · Citicorp Center · Millennium Bridge · Apollo 13 · the 2003 blackout · Hyatt Regency
https://therepository.gumroad.com/l/failure-atlas
PRIMARY SOURCES
- Report of the President's Commission on the Accident at Three Mile Island ("Kemeny Commission Report"), October 1979 — read directly from a text-layer PDF, "Account of the Accident," pp. 81-99: https://www.tmia.com/sites/tmia.com/files/media/Presidents-Commission.pdf
- Full report, alternate archive copy: https://archive.org/details/three-mile-island-report
- The Davis-Besse precursor (September 1977) and NRC inspector James Creswell's March 1979 warning to the Commission: corroborated via independent secondary historical and academic sources on nuclear safety history, not read from the NRC's own technical case file in this production.
The 23 technical plates in this video are illustrations generated for the channel by a diffusion image model, styled to match its cyanotype identity. They are diagrams of the system, not photographs of the hardware, and no person is depicted in any of them.
Root Cause investigates why engineered systems fail, using the official investigation reports and the primary technical literature. Sources for this episode are linked above.
The technical drawings in this video are cyanotype-style illustrations produced for the channel. They are diagrams, not photographs of the real hardware or the actual control room. The charts and dimensioned comparisons are drawn from the figures and text in the sources listed above.