A Matter of Millimeters: The Story of Qantas Flight 32

The Qantas A380 engine disintegration in 2010

On November 4, 2010, a Qantas A380 suffered a catastrophic engine failure minutes after takeoff from Singapore, hurling turbine fragments through the wing and fuselage. The explosion crippled nearly every major system, but the five pilots—with 140 years of combined experience—managed to land the plane safely, sparing all 469 aboard. Investigators traced the cause to a single oil pipe with a wall just fractions of a millimeter too thin. This detailed account explores the manufacturing flaw, the chain of failures, and the design safeguards that prevented a disaster.

How this seemingly tiny defect came about, and how it nearly brought down the world’s largest passenger plane, represent a story equally as fascinating as that of the flight itself.
  1. paulmooreparks

    I flew on this exact same plane, VH-OQA, on November 4, 2019, from Singapore to Melbourne.

    While I was sitting at the gate, I remembered that line from Rain Main about "Qantas never crashed," and since that flight would be my first time flying on an A380, I wondered if any had crashed or had any other incidents. I looked up "a380 crash" on my phone, and what do you know? The first hit was a Wikipedia article about a Qantas A380 uncontained engine failure, which had occurred four minutes after takeoff... from Changi! Even wilder was the fact that it had happened 9 years earlier. When I looked up the plane's registration number on Flightradar24, I realized that was the same plane I was flying to Melbourne on.

  2. u1hcw9nx

    Turbine disk failure is one thing that can down a plane, and you can only reduce the probability so much.

    Fan blades and turbine blades can be contained by containment cases if they break off, but turbine disks can't. When a disk breaks, it's an uncontained engine failure. A 20 kg disk fragment flying at Mach 1 goes through everything.

    Airframes are have a 30-degree fragment spread cone around every disk stage. Airframes are designed so that no single fragment can destroy all redundant systems at once in this zone (flight controls, fuel lines, and hydraulic systems). Jet fuel cannot be stored in the wings in this zone.

  3. exceptione

    > The detailed software allowed them to enter various parameters including the weather, runway condition, and any systems failures, and then calculate whether it was possible to land. But when everything had been entered, the program spit out an unhelpful answer: “no result.”

    > When calculating the landing distance, the software applied a generic “operational coefficient” to account conservatively for variations in pilot techniques that could result in less efficient deceleration. The problem, as investigators would later discover, was that the software applied the coefficient again whenever another system failure was added. With so many system failures on the aircraft, the coefficient was applied a total of 9 times, resulting in a calculated landing distance considerably greater than the length of the available runway. However, Check Captain Evans was able to fix the problem by manually entering their actual landing weight, overriding the program’s assumption of a maximum landing weight. By specifying a landing weight in excess of the maximum, the system logic changed to apply the operational coefficient only once — for unrelated and obscure reasons — and lo and behold, when he ran the numbers this time, the computer said they could just barely land on any of the 4,000-meter runways at Singapore Changi Airport, with only 100 meters to spare.

    This reeks so much of if-then-else programming as opposed to making a well-typed conceptual model computable.

  4. userbinator

    Plane engines are extremely highly optimised, and the design margins are basically at the limit of what regulations allow, which is IMHO why the tiniest of errors can have huge consequences. However, in this case it sounds like the manufacturing process was such that it invited misalignment:

    Finally, working from the inside through the inner hub counter bore, the stub pipe counter bore would be drilled to a specified depth to accommodate the filter. (This was the bore that was later found to be offset by half a millimeter.)

    Why not machine the stub pipes to their desired dimensions, including the drilling, and then install them? That way, no in-situ drilling, with that accompanying risk of misalignment, would even be necessary. Even if they decided such drilling was unavoidable, a drill with a pilot (no pun intended) would've kept the holes as concentric as needed. (Disclaimer: Not a professional machinist; but have done some lathe and mill work.)

    The temperature inside this buffer space was likely between 365 and 375˚C, well above the 280-degree auto-ignition temperature of the engine oil, so the spray immediately ignited.

    It's worth noting that due to fire risk, most planes use non-flammable hydraulic fluid, although it's not without its own dangers, so perhaps non-flammable engine oil was considered but ultimately decided against: https://en.wikipedia.org/wiki/Skydrol

  5. brcmthrowaway

    What was more serious - this or the Hudson incident?

  6. CursedSilicon

    One of my favourite memories of flying Qantas when I was younger was the inflight entertainment.

    If memory serves, they were celebrating some sort of milestone like "60 years without a fatal accident" or similar. Quite an impressive feat!

    I'm unclear if it was directly related. But the Qantas inflight entertainment system on our flight from Sydney to Los Angeles meanwhile contained about 12 seasons of the National Geographic series "Air Crash Investigation" (Mayday: Air Disasters for Americans)

    I will admit that show made an 18 hour slog of a flight significantly more enjoyable

  7. libraryofbabel

    I once heard someone describe Admiral Cloudberg's air crash investigation blog as "the best thing on the Internet" and I still think that might be true. She is a great researcher and a superb writer, which stands out all the more these days in these fallen times of load-bearing AI slop. Her blog is beloved of both aviation geeks and, for obvious reasons, SREs (and other engineers).

    She recently posted what's basically her magnum opus, on the Potomac river midair collision.[0] It's the length of a short book. I'm working my way through it; I'm taking a flight today, and I'll probably read it on the plane tonight.

    This article, on how an A380 with 469 souls aboard almost crashed, but didn't, is one of her best. I like it because it's a happy ending, and a story of the combined effects of good engineering design (the astonishing degree of redundancy built into the A380 proved just enough to prevent catastrophe), and human troubleshooting under pressure in the cockpit by some smart people with vast experience who remained calm throughout. (Another favorite article of her, on the Air France 447 crash, tells the exact opposite story: poor systems design combined with pilots basically losing the most basic ability to aviate in the heat of the moment. That one is a much darker read.[1])

    [0] https://admiralcloudberg.medium.com/reaping-the-whirlwind-in...

    [1] https://admiralcloudberg.medium.com/the-long-way-down-the-cr...

  8. 00N8

    > the in-flight entertainment system, which featured a live view of the aircraft from a tail-mounted camera. The digital stream clearly showed a much more literal stream of fuel pouring from the left wing and into the aircraft’s wake, which was also visible with the naked eye from the lower deck. Johnson proceeded down to check for himself, at which point he also observed for the first time that there were two gaping holes in the top of the left wing, surrounded by jagged metal, where the turbine disk fragments had exited.

    > According to Check Captain David Evans, the cabin crew were concerned that so many passengers were watching the live feed from the tail camera, but in a collective decision, the pilots elected not to turn it off because, in their view, the feed suddenly cutting out would probably be more alarming than anything that could be seen on it.

    I appreciate this part. If I were ever in a similar situation, I'd want to be able to see what's going on. Suddenly cutting the feed would send me straight into a panic.

More from this day

2026-09-02