5 Engineering Mistakes That Should Have Been Caught
Every disaster on this list started with something small. A wrong unit. A design change no one double-checked. A number on a spreadsheet that was too low. These were not freak accidents. They were failures that someone, at some point, had the information to prevent.
Five engineering mistakes. Five catastrophes. All of them should have been caught.
1. Mars Climate Orbiter (1999): The Unit Conversion Error
On September 23, 1999, NASA’s Mars Climate Orbiter fired its main engine to enter orbit around Mars. It was never heard from again. The spacecraft passed behind the planet at an altitude of just 57 kilometers, far too low. It either burned up in the Martian atmosphere or skipped off it and tumbled into space.
The cause was almost absurdly simple. Lockheed Martin, which built the spacecraft, used imperial units (pound-force seconds) for thruster data. NASA’s Jet Propulsion Laboratory expected metric units (newton-seconds). No one caught the mismatch.
For nine months, as the orbiter cruised toward Mars, navigators noticed small trajectory discrepancies. They filed reports. They flagged concerns. But the anomalies were small enough that the team kept adjusting course rather than investigating the root cause.
The fix would have been trivial: a unit conversion check during integration testing, or a single line of code to convert the thruster output. The Mars Climate Orbiter cost $327.6 million. It was destroyed by a problem a first-year physics student could have solved.
2. Hyatt Regency Walkway Collapse (1981): The Design Change That Doubled the Load
On July 17, 1981, the atrium of the Hyatt Regency Hotel in Kansas City, Missouri, was packed with over 1,600 people attending a tea dance. Two suspended walkways, one on the second floor and one on the fourth, hung from the ceiling on steel rods. At 7:05 p.m., the fourth-floor walkway collapsed onto the second-floor walkway, and both crashed to the lobby below.
114 people were killed. Over 200 more were injured. It remains the deadliest structural collapse in U.S. history outside of deliberate attacks.
The original design called for a single set of continuous steel rods running from the ceiling through both walkways. During construction, the fabricator proposed a change: instead of one long rod, use two shorter rods. The upper walkway would hang from the ceiling, and the lower walkway would hang from the upper one.
The change seemed minor. It was not. In the original design, each rod connection bore the weight of one walkway. In the revised design, the connection on the fourth-floor walkway bore the weight of both. The load on that connection doubled.
The structural engineer’s firm approved the change without performing a new load calculation. The connection was already under-designed for even the original single-walkway load. With two walkways hanging from it, failure was inevitable. All it took was enough people standing on the walkways at the same time.
The engineers who approved the change lost their licenses. The fabricator who proposed it said he assumed the engineers had checked it. The engineers said they assumed the fabricator understood the structural implications. Nobody checked.
3. I-35W Bridge Collapse (2007): Undersized Gusset Plates
On August 1, 2007, the Interstate 35W bridge over the Mississippi River in Minneapolis collapsed during evening rush hour. The entire 1,907-foot steel truss structure fell into the river in seconds. Thirteen people were killed. 145 were injured.
The bridge had been in service since 1967. Inspectors had flagged it as “structurally deficient” as early as 2001. The state rated it a 50 out of 120 on its sufficiency scale. But “structurally deficient” is a maintenance classification, not an imminent danger warning, and hundreds of U.S. bridges carry the same label.
The National Transportation Safety Board investigation found the actual cause: the gusset plates, the steel plates that connect the bridge’s truss members at each joint, were undersized. They were roughly half the thickness they should have been. This was not wear and tear. It was an error in the original 1960s design.
For 40 years, the bridge stood on gusset plates that were too thin. They held because the bridge’s safety margin, while smaller than intended, was still positive under normal loads. But over the decades, the bridge was modified. Additional concrete was added to the road surface. On the day of the collapse, construction equipment and materials were staged on the bridge deck, concentrating extra weight directly over the weakest joints.
The undersized gusset plates had been visible in every inspection. They were measured. They were photographed. But no one ever checked the original design calculations against the actual plate dimensions. The error hid in plain sight for four decades.
4. Space Shuttle Challenger (1986): O-Ring Failure in Cold Weather
On January 28, 1986, the Space Shuttle Challenger broke apart 73 seconds after launch, killing all seven crew members. The immediate cause was the failure of an O-ring seal in the right solid rocket booster. Hot combustion gases burned through the seal and reached the external fuel tank, triggering a catastrophic structural failure.
The O-ring problem was not new. Engineers at Morton Thiokol, the company that built the solid rocket boosters, had been warning NASA about O-ring erosion for years. After previous flights, inspectors found that the rubber O-rings showed signs of heat damage, especially in colder temperatures. The rings were designed to flex and seal the joint between booster segments. In cold weather, the rubber stiffened and lost its ability to seal properly.
The night before the Challenger launch, temperatures at Kennedy Space Center dropped to 36 degrees Fahrenheit, well below any previous launch temperature. Morton Thiokol engineers held a teleconference with NASA and recommended delaying the launch. They presented data showing the correlation between cold temperatures and O-ring damage.
NASA managers pushed back. They asked Thiokol to reconsider. Under pressure, Thiokol’s management overruled their own engineers and approved the launch.
The next morning, Challenger lifted off into a clear blue sky. The O-ring in the right booster never sealed. Within seconds, a plume of flame was visible on the side of the booster. Just over a minute later, the shuttle was gone.
The Rogers Commission, appointed by President Reagan to investigate, found that NASA’s decision-making culture had normalized the O-ring risk. Because previous flights had survived despite O-ring erosion, managers treated survival as evidence of safety rather than evidence of luck. Physicist Richard Feynman, a member of the commission, demonstrated the problem on live television by dropping a piece of O-ring rubber into a glass of ice water and showing that it lost its flexibility.
The data was there. The engineers raised the alarm. Management overruled them. Seven people died because a rubber seal got cold.
5. Teton Dam (1976): Building on Permeable Rock
On June 5, 1976, the Teton Dam in southeastern Idaho collapsed during its first filling. The dam was a 305-foot-tall earthfill structure built across a canyon of highly fractured volcanic rock. When the reservoir reached near-capacity for the first time, water seeped through the porous foundation and through the dam itself. The structure eroded from the inside out, and by midday, the entire dam gave way.
The flood killed 11 people and caused over $2 billion in damage (adjusted for inflation). It destroyed the towns of Wilford, Sugar City, and Rexburg. Over 13,000 head of cattle drowned.
The geology of the Teton Dam site was a known problem from the start. The canyon walls were made of welded tuff and rhyolite, volcanic rock riddled with fractures, fissures, and voids. Multiple geologists and engineers who reviewed the site raised concerns about its suitability for an earthfill dam. The rock was too permeable. Water would find pathways through it.
The Bureau of Reclamation, which designed and built the dam, acknowledged the challenging geology but believed it could be managed with grouting, injecting cement into the rock to seal the cracks. The grouting program was extensive but ultimately inadequate. The fractures were too numerous, too deep, and too interconnected. Water found routes that the grout could not reach.
During the first filling in the spring of 1976, springs appeared downstream of the dam. Wet spots formed on the dam face. On the morning of June 5, workers spotted water seeping from the dam’s embankment. Within hours, the seepage became a torrent. The dam eroded from the inside, creating a tunnel through the structure that widened until the entire dam collapsed.
An independent review panel concluded that the dam should not have been built at that site with that design. The permeable foundation was a known risk. The grouting was a mitigation strategy, not a solution. The warning signs during construction and filling were clear, but the project had too much momentum and too much political support to stop.
One Small Change
A unit conversion. A load calculation. A plate thickness check. A launch-temperature threshold. A geology review. Each of these disasters traces back to a single, fixable problem that someone had the knowledge and the opportunity to catch.
None of them required new technology. None of them required extraordinary insight. They required someone to pause and verify a number, question a change, or listen to the engineers who were already raising the alarm.
The pattern is always the same. A small error enters the system early. It passes through reviews, approvals, and inspections without being caught. It accumulates risk quietly, sometimes for years, until conditions align and the margin of safety disappears. Then people die.
Engineering is not about building things that never fail. It is about catching the failures before they reach the real world. Every disaster on this list is proof of what happens when that process breaks down. Not because the problem was too complex, but because someone assumed it had already been checked.