The encyclopedia · Legal & Compliance · Legal decision · 2018
Boeing's 737 MAX had a hidden flight-control flaw that killed 346 people in two crashes
A flight-control system called MCAS, fed by a single faulty sensor, pushed two 737 MAX jets into fatal dives — 346 dead. Boeing barely told pilots it existed.
Boeing · 2018-10-29
What happened
The Boeing 737 MAX was the latest version of Boeing's best-selling airliner, rushed to market to compete with the fuel-efficient Airbus A320neo. To handle the plane's larger, repositioned engines, Boeing added a software system called MCAS, which could automatically push the nose down if it sensed a stall risk. To keep the MAX handling like earlier 737s — and avoid expensive simulator training — Boeing designed MCAS to rely on data from just one of the plane's two angle-of-attack sensors, and did not fully tell pilots the system existed or how to respond.
On October 29, 2018, Lion Air Flight 610 crashed into the sea off Indonesia minutes after takeoff, killing all 189 people on board. A faulty angle-of-attack sensor had fed MCAS erroneous data, repeatedly forcing the nose down while pilots struggled to understand and control the aircraft. Less than five months later, on March 10, 2019, Ethiopian Airlines Flight 302 crashed in nearly identical circumstances, killing all 157 on board. The two disasters killed 346 people in all.
After the second crash, regulators worldwide grounded the entire 737 MAX fleet; the US FAA, which had certified the plane, was among the last to act. Investigations found Boeing had concealed MCAS from operators and regulators, and that the FAA's certification had been inadequate. The MAX was grounded for twenty months, until November 2020, while Boeing redesigned the system to use both sensors and required new pilot training. In January 2021, Boeing agreed to pay more than $2.5 billion to resolve a US criminal investigation into the crashes.
Why it happened
- To avoid costly pilot retraining and speed certification, Boeing designed MCAS to depend on a single angle-of-attack sensor — a single point of failure on a flight-control system.
- Boeing did not adequately disclose MCAS to pilots or regulators, so crews did not know the system existed or how to counteract it when it malfunctioned.
- The FAA's certification process, which delegated significant oversight to Boeing itself, failed to catch the design's risks.
- Commercial pressure to match the Airbus A320neo quickly drove decisions that prioritized speed and cost over redundancy and transparency.
The lesson
A safety system that can override the pilots must fail safe, be disclosed to them, and never depend on a single sensor. Boeing cut corners on all three to certify the 737 MAX fast — 346 people died.
Aftermath
The 737 MAX disasters are among the most studied failures in aviation history. They cost 346 lives, led to the longest grounding of a US airliner, cost Boeing tens of billions in settlements, fines and lost orders, and damaged a century-old reputation. Boeing's former chief technical pilot was charged (later acquitted); the company entered a deferred prosecution agreement. The case shows how commercial pressure, a single-point-of-failure design, inadequate disclosure and weak oversight combine into catastrophe — and why safety redundancy and transparency must never be traded for speed or cost.
Sources
- Boeing 737 MAX — Wikipedia (MCAS, Lion Air 610 & Ethiopian 302, 346 dead, grounding, $2.5B settlement)
- The Seattle Times — Failed certification: FAA missed safety issues in the 737 MAX system implicated in the Lion Air crash (archived)
spotted an error? The club wants to know.
More like this
Challenger broke apart 73 seconds after launch — a known O-ring flaw killed all seven crew
Volkswagen programmed 11 million cars to cheat emissions tests
Nikola's truck rolled downhill — and the $1B fraud rolled into court
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.