Back to the archive

The encyclopedia · Legal & Compliance · Legal decision · 2018

Boeing's 737 MAX had a hidden flight-control flaw that killed 346 people in two crashes

A flight-control system called MCAS, fed by a single faulty sensor, pushed two 737 MAX jets into fatal dives — 346 dead. Boeing barely told pilots it existed.

Boeing · 2018-10-29

What happened

The Boeing 737 MAX was the latest version of Boeing's best-selling airliner, rushed to market to compete with the fuel-efficient Airbus A320neo. To handle the plane's larger, repositioned engines, Boeing added a software system called MCAS, which could automatically push the nose down if it sensed a stall risk. To keep the MAX handling like earlier 737s — and avoid expensive simulator training — Boeing designed MCAS to rely on data from just one of the plane's two angle-of-attack sensors, and did not fully tell pilots the system existed or how to respond.

On October 29, 2018, Lion Air Flight 610 crashed into the sea off Indonesia minutes after takeoff, killing all 189 people on board. A faulty angle-of-attack sensor had fed MCAS erroneous data, repeatedly forcing the nose down while pilots struggled to understand and control the aircraft. Less than five months later, on March 10, 2019, Ethiopian Airlines Flight 302 crashed in nearly identical circumstances, killing all 157 on board. The two disasters killed 346 people in all.

After the second crash, regulators worldwide grounded the entire 737 MAX fleet; the US FAA, which had certified the plane, was among the last to act. Investigations found Boeing had concealed MCAS from operators and regulators, and that the FAA's certification had been inadequate. The MAX was grounded for twenty months, until November 2020, while Boeing redesigned the system to use both sensors and required new pilot training. In January 2021, Boeing agreed to pay more than $2.5 billion to resolve a US criminal investigation into the crashes.

Why it happened

  • To avoid costly pilot retraining and speed certification, Boeing designed MCAS to depend on a single angle-of-attack sensor — a single point of failure on a flight-control system.
  • Boeing did not adequately disclose MCAS to pilots or regulators, so crews did not know the system existed or how to counteract it when it malfunctioned.
  • The FAA's certification process, which delegated significant oversight to Boeing itself, failed to catch the design's risks.
  • Commercial pressure to match the Airbus A320neo quickly drove decisions that prioritized speed and cost over redundancy and transparency.
What it cost346 dead; $2.5B settlement; 20-month groundingcatastrophic

The lesson

A safety system that can override the pilots must fail safe, be disclosed to them, and never depend on a single sensor. Boeing cut corners on all three to certify the 737 MAX fast — 346 people died.

Aftermath

The 737 MAX disasters are among the most studied failures in aviation history. They cost 346 lives, led to the longest grounding of a US airliner, cost Boeing tens of billions in settlements, fines and lost orders, and damaged a century-old reputation. Boeing's former chief technical pilot was charged (later acquitted); the company entered a deferred prosecution agreement. The case shows how commercial pressure, a single-point-of-failure design, inadequate disclosure and weak oversight combine into catastrophe — and why safety redundancy and transparency must never be traded for speed or cost.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →