The Boeing 737 MAX Disaster Explained: The Crashes, MCAS And What Boeing Knew

Boeing 737 MAX: The Software, Warnings And Decisions Behind 346 Deaths

The Fatal Design Decisions Behind Two Crashes

How A New Aircraft Became A Global Crisis

Two new Boeing passenger aircraft crashed less than five months apart. All 346 people aboard them died. At the centre of both disasters was a flight-control system most passengers had never heard of and many pilots had received little or no training about: MCAS.

But reducing the Boeing 737 MAX disaster to a software malfunction misses what made the episode so important. Investigations eventually exposed a deeper chain involving aircraft design, assumptions about how quickly pilots would respond to emergencies, Boeing's determination to preserve commonality with older 737s, weaknesses in regulatory oversight and crucial information that did not reach the pilots expected to control the aircraft.

The story still matters. The MAX returned to commercial service after extensive modifications, but scrutiny of Boeing's engineering, manufacturing and safety culture continued long afterwards. As recently as July 2026, the Federal Aviation Administration was still describing enhanced inspections and oversight as it cautiously restored some certification authority that Boeing had lost following the MAX crisis.

Why Boeing Built The 737 MAX

The origins of the disaster began years before either aircraft crashed. Boeing and Airbus were locked in one of the most valuable industrial competitions in the world, fighting for airlines buying thousands of single-aisle passenger jets.

Airbus launched the A320neo, offering airlines substantially improved fuel efficiency without requiring them to abandon a familiar aircraft family. Boeing needed an answer.

Rather than creating an entirely new aircraft, Boeing developed another generation of the enormously successful 737. The 737 MAX would use larger, more efficient CFM LEAP engines while retaining enough commonality with existing 737s to make it attractive to airlines already operating Boeing fleets.

That commonality mattered enormously. Airlines do not simply pay for aircraft. They pay for pilot training, simulators, maintenance programmes, spare parts, scheduling changes and the disruption caused by introducing a different aircraft type.

A new aeroplane requiring expensive simulator conversion training would therefore weaken one of Boeing's most powerful commercial advantages.

The resulting aircraft was remarkably successful commercially. Thousands were ordered. But changing the engines also altered some of the aircraft's aerodynamic characteristics.

The larger engines were positioned differently relative to earlier 737 versions. Under particular high angle-of-attack conditions, the MAX could develop a stronger tendency for its nose to rise.

Boeing introduced software intended to compensate for that characteristic.

Its name was the Maneuvering Characteristics Augmentation System.

MCAS.

What MCAS Actually Did

MCAS was designed to operate automatically in specific circumstances during manual flight. Its purpose was not primarily to prevent an ordinary stall in the way some early descriptions suggested. It was intended to make the MAX's handling characteristics meet certification requirements and feel sufficiently similar to earlier members of the 737 family during certain manoeuvres.

The system could command movement of the horizontal stabiliser, producing a nose-down pitching effect.

That sounds manageable until one critical feature of the original design is understood.

MCAS could be triggered using information from a single angle-of-attack sensor.

Angle of attack describes the relationship between the aircraft's wing and the airflow approaching it. When the angle becomes too high, an aircraft can approach an aerodynamic stall.

The 737 MAX had two angle-of-attack sensors, but the original MCAS logic could act on the reading supplied by only one of them during a flight.

If that sensor supplied an erroneous high value, MCAS could effectively be told that the aircraft was approaching a dangerous angle even when it was not.

The FAA later summarised the resulting danger clearly: one erroneously high angle-of-attack input could cause MCAS to repeatedly command nose-down stabiliser trim, potentially making the aircraft increasingly difficult for the pilots to control.

That vulnerability became catastrophic on October 29, 2018.

Lion Air Flight 610

Lion Air Flight 610 departed Jakarta for Pangkal Pinang in Indonesia shortly after 6.20 a.m. local time.

The aircraft was a Boeing 737 MAX 8.

There were 189 people aboard.

Almost immediately, the pilots were dealing with abnormal information and control problems. The aircraft's left angle-of-attack sensor was producing an incorrect reading.

That erroneous information affected more than one cockpit system. The pilots faced conflicting indications while trying to fly an aircraft that repeatedly attempted to trim its nose downward.

MCAS activated.

The crew countered the nose-down movement using electric trim.

MCAS activated again.

The pilots countered it again.

The pattern repeated.

This distinction is central to understanding the disaster. The aircraft did not simply receive one incorrect command that the pilots failed to correct. The control system could repeatedly reapply nose-down stabiliser trim after the crew had intervened.

The pilots fought the aircraft for several minutes.

They did not recover control.

Flight 610 plunged into the Java Sea around 13 minutes after take-off.

Every person aboard was killed.

There Had Already Been A Warning On The Same Aircraft

One of the most disturbing parts of the Lion Air story is that the aircraft had suffered a similar problem on its previous flight.

During that earlier journey, faulty angle-of-attack information had also produced abnormal indications and unwanted nose-down trim.

But that flight ended safely.

An off-duty pilot travelling in the cockpit helped the operating crew diagnose the stabiliser problem, and the pilots used the stabiliser trim cut-out switches to stop the automatic trim behaviour.

The aircraft nevertheless returned to service.

Maintenance work was performed, including replacement of the angle-of-attack sensor, but the replacement sensor itself supplied erroneous information on Flight 610.

Investigators eventually uncovered a complicated chain involving maintenance, sensor calibration, cockpit warnings, pilot actions, aircraft documentation and MCAS itself.

Yet the fundamental design problem was stark: erroneous information from one sensor could trigger an automated system capable of repeatedly moving a flight-control surface.

The disaster should have transformed the understanding of MCAS immediately.

Five months later, another MAX took off.

Ethiopian Airlines Flight 302

On March 10, 2019, Ethiopian Airlines Flight 302 departed Addis Ababa for Nairobi.

The aircraft was another Boeing 737 MAX 8.

There were 157 people aboard.

Shortly after take-off, the left angle-of-attack sensor began transmitting an extreme and incorrect reading. Investigators later disagreed over exactly what caused the sensor failure, with the US National Transportation Safety Board concluding that the sensor vane was most likely struck and separated after contact with a foreign object, probably a bird.

The cockpit rapidly became hostile.

The pilots received multiple abnormal indications. The stick shaker activated. Airspeed and altitude information disagreed.

Then MCAS began commanding nose-down stabiliser movement.

The crew fought back.

Unlike the Lion Air pilots, they knew about the stabiliser cut-out procedure that had been emphasised after the first disaster. They moved the cut-out switches, stopping electrical trim commands.

But another problem emerged.

By then, aerodynamic forces had made manually adjusting the stabiliser extremely difficult. The aircraft was travelling fast and the pilots were applying substantial force to keep the nose up.

Electrical trim was eventually restored.

MCAS activated again.

Approximately six minutes after take-off, the aircraft struck the ground near Bishoftu at enormous speed.

All 157 people aboard died.

The similarities between the two crashes could no longer be treated as coincidence.

346 People Had Died

Lion Air Flight 610 killed 189 people.

Ethiopian Airlines Flight 302 killed 157.

Together, the two accidents killed 346 passengers and crew.

Both involved erroneous angle-of-attack information.

Both involved MCAS.

Both confronted pilots with a combination of unexpected automatic stabiliser movements and other cockpit warnings.

And in both cases the pilots behaved differently from assumptions that had been used during the aircraft's safety analysis.

That last point became one of the most important findings of the entire investigation.

Boeing and the FAA had assumed that trained pilots would recognise certain unexpected stabiliser movements and respond appropriately within a short period.

Reality proved considerably messier.

The crews were not sitting inside simulators waiting for an isolated MCAS malfunction.

They faced stick shakers, disagreeing instruments, warning messages, control forces, radio communications, rapidly changing altitude and speed, and an aircraft behaving in ways they did not necessarily understand.

The NTSB later concluded that the pilots' responses in the accident scenarios did not match the assumptions underlying the certification analysis. It urged regulators to account more realistically for how humans react when several warnings and failures arrive at once.

Why Had Many Pilots Barely Heard Of MCAS?

This became one of the defining questions.

MCAS was not initially emphasised in the documentation and training supplied to ordinary MAX pilots.

That was not an accidental omission from one airline's briefing.

The US Department of Justice later established that information concerning an important expansion of MCAS's operating range was withheld from the FAA group responsible for determining pilot-training requirements.

According to the Justice Department's statement of facts, two Boeing flight technical pilots discovered in 2016 that MCAS could activate across a broader speed range than had previously been understood by the regulator.

That information was not properly disclosed to the FAA Aircraft Evaluation Group.

Consequently, references to MCAS were removed from the final version of the MAX Flight Standardization Board report, and US airline pilot manuals and training materials did not contain information about the system.

The implications were extraordinary.

An automatic system capable of moving the aircraft's stabiliser could activate without pilots necessarily knowing the system existed.

Pilots were expected to diagnose the resulting behaviour using their existing knowledge of stabiliser malfunctions.

That philosophy depended heavily on another assumption: the crew would recognise what was happening quickly enough.

What Boeing Knew About Pilot Response

Investigations later revealed evidence that should have complicated that assumption.

During simulator testing in 2012, Boeing encountered an MCAS-related scenario in which a pilot took more than ten seconds to respond to unexpected activation.

The congressional investigation into the MAX said the pilot described the situation as potentially "catastrophic".

That mattered because certification analysis depended partly on assumptions about pilot reaction times.

If a real crew did not recognise the problem almost immediately, the aircraft could continue trimming towards a dangerous nose-down position.

Congressional investigators concluded that crucial information about those tests was not adequately shared with the FAA.

The same investigation found something broader than one withheld data point.

It described a culture in which cost, schedule, training requirements and regulatory considerations repeatedly interacted with engineering decisions.

The Pressure To Avoid Simulator Training

One of Boeing's major selling points was that pilots already qualified on older 737s could transition to the MAX without extensive simulator training.

That mattered commercially.

Simulator training is expensive. It takes pilots off flying schedules, creates logistical headaches for airlines and makes switching aircraft types more disruptive.

Boeing therefore had a powerful incentive to preserve a relatively straightforward transition from the 737 Next Generation to the 737 MAX.

Congressional investigators concluded that avoiding more demanding training requirements exerted significant influence over the programme.

This does not mean Boeing engineers deliberately designed an unsafe aeroplane to save the price of simulator sessions.

The real failure was more systemic.

Commercial objectives shaped design constraints. Those constraints influenced how new technology was introduced. Assumptions were made about how pilots would interact with that technology. Certification processes then assessed the aircraft using those assumptions.

Each individual decision could appear manageable.

Together they created vulnerability.

A System That Became More Powerful

MCAS also changed during the MAX's development.

The early version had more limited authority.

As testing continued, the system's ability to command stabiliser movement increased and its operating envelope expanded.

Those changes were significant because the hazard presented by an erroneous activation increased with them.

Yet the flow of information to regulators and pilots did not expand proportionately.

The Justice Department case later focused specifically on Boeing flight technical pilots withholding information about MCAS from the FAA unit responsible for training requirements.

Boeing eventually admitted responsibility for those acts as part of a 2021 deferred prosecution agreement. The company agreed to pay more than $2.5 billion, including a $243.6 million criminal monetary penalty, $1.77 billion in compensation for airline customers and a $500 million fund for crash victims' beneficiaries.

That criminal case later became the subject of further proceedings concerning Boeing's compliance with the agreement and the rights of victims' families. The litigation continued for years after the aircraft itself had returned to the sky.

Boeing Was Not The Only Institution That Failed

The MAX crisis was also a regulatory failure.

The FAA certifies aircraft in the United States, but modern certification relies heavily on delegated authority.

Under the Organization Designation Authorization system, approved employees within manufacturers can perform some certification tasks on the FAA's behalf.

There are practical reasons for delegation. Modern airliners contain millions of components and extraordinarily complex systems. Regulators cannot personally repeat every calculation or inspect every engineering decision.

But delegation creates an obvious tension.

Employees effectively carrying out regulatory work may still exist inside the corporate environment of the manufacturer whose aircraft is being certified.

A Joint Authorities Technical Review assembled after the crashes found weaknesses in the MAX certification process, including inadequate assessment of how design changes affected pilot workload and training.

The congressional investigation went further, concluding that oversight by the FAA had been grossly insufficient and that Boeing's technical assumptions, transparency failures and production pressures combined with shortcomings in the certification system.

Production Pressure Inside Boeing

The pressure surrounding the MAX was not theoretical.

Boeing was trying to defend one of the most valuable markets in commercial aviation against the Airbus A320neo.

The congressional investigation found that managers used countdown clocks to emphasise programme milestones and that employees working within the certification structure reported concerns about undue influence.

In a 2016 Boeing survey, 39 per cent of authorised representatives surveyed said they believed they had experienced undue influence.

Production pressure later reached the factory floor.

Senior Boeing manager Ed Pierson raised concerns in 2018 about conditions at the Renton 737 factory, including worker fatigue, schedule pressure and quality-control problems.

The congressional report concluded that Boeing continued increasing production despite those warnings.

There is an important distinction here.

Investigators did not establish that production-line problems identified by Pierson directly caused either MCAS crash.

Their significance is cultural.

They added to evidence of an organisation under enormous pressure to build aircraft quickly, preserve schedules, contain costs and defend market share.

In a safety-critical company, organisational culture matters because catastrophic accidents rarely begin with one spectacular decision.

They begin with small compromises becoming normal.

Why The FAA Grounded The MAX

After Ethiopian Airlines Flight 302 crashed, regulators around the world began grounding the 737 MAX.

The United States initially stopped short.

On March 13, 2019, the FAA also grounded the aircraft.

The worldwide MAX fleet effectively disappeared from passenger service.

Boeing now faced a technical challenge much larger than fixing one line of software.

Regulators needed confidence that MCAS itself had been redesigned, that other flight-control vulnerabilities had been investigated, that pilots would understand the system and that the certification process had properly tested failure scenarios.

The grounding lasted approximately 20 months in the United States.

How MCAS Was Changed

The redesigned system removed one of the most dangerous features of the original architecture.

MCAS would no longer rely unquestioningly on a single angle-of-attack sensor.

The updated system compares information from both sensors before activation.

If the readings disagree significantly, MCAS is disabled for that flight rather than acting on potentially erroneous information.

Its authority was also limited.

The revised MCAS cannot repeatedly command progressively greater nose-down stabiliser movement in the same way as the original system.

Other software, wiring, procedures, documentation and training requirements were reviewed as part of the return-to-service process.

Pilots received specific MAX training, including simulator training dealing with MCAS and stabiliser problems.

The FAA said its changes were designed to address the unsafe condition demonstrated by the accident data: a single erroneous angle-of-attack input causing repeated nose-down trim and potentially overwhelming the crew's ability to maintain control.

Was The Boeing 737 MAX Made Safe?

In November 2020, the FAA rescinded its grounding order after requiring software modifications, inspections, revised operating procedures and additional pilot training.

Other regulators performed their own assessments before allowing the aircraft to return.

That process produced an aeroplane materially different from the aircraft involved in the two disasters, particularly in how MCAS responds to sensor data and how pilots are trained to deal with it.

Millions of MAX passenger flights have since been completed.

That does not erase what happened.

Nor does every later problem involving a MAX aircraft have anything to do with MCAS.

This distinction became important following the January 2024 Alaska Airlines Flight 1282 accident, when a door plug separated from a 737 MAX 9 shortly after departure from Portland.

That event exposed serious manufacturing and quality-control concerns, but it was fundamentally different from the MCAS failures that caused the original MAX grounding.

The FAA responded by temporarily grounding affected MAX 9 aircraft, intensifying inspections and refusing to allow Boeing to expand MAX production until quality-control issues were addressed.

The MAX Disaster Was Bigger Than MCAS

MCAS became the symbol of the Boeing 737 MAX crisis because it connected the two fatal crashes.

But MCAS alone does not explain why 346 people died.

The deeper story involved the interaction between software and human beings.

It involved a safety architecture in which one faulty sensor could trigger powerful automated action.

It involved assumptions about how pilots would behave under severe workload.

It involved critical information that did not reach the regulator responsible for determining training requirements.

It involved pressure to preserve the MAX's similarity to previous 737s.

It involved regulatory delegation and an oversight structure that failed to expose the danger before passengers encountered it.

And it involved an organisation under intense commercial pressure from its greatest rival.

This is what makes the MAX disaster so important beyond aviation.

Complex systems rarely fail because one component suddenly becomes evil or one person deliberately chooses catastrophe.

They fail when multiple safeguards that are supposed to compensate for one another quietly become dependent on the same optimistic assumptions.

What Boeing Knew — And What It Did Not

It would be inaccurate to say Boeing knew that the 737 MAX would crash and allowed it to fly anyway.

The evidence does not establish that.

What the investigations establish is more specific and, in some respects, more disturbing.

People inside Boeing knew MCAS had evolved.

Boeing flight technical pilots learned that its operational envelope was broader than the FAA training specialists had been led to understand.

That information was not properly communicated.

Testing had demonstrated that unexpected MCAS behaviour could create a difficult pilot-response scenario.

The aircraft nevertheless entered commercial service without ordinary pilots receiving detailed MCAS training.

Boeing also knew that avoiding expensive simulator training was commercially important to the MAX programme.

And the broader organisation contained employees raising concerns about schedule pressure, production conditions and safety culture.

Those facts do not prove that Boeing expected either crash.

They show that opportunities existed to understand the accumulating risk before 346 people died.

That is the central failure.

The Lasting Lesson Of The 737 MAX

The most dangerous part of the original 737 MAX was not simply an automated system pushing the nose down.

It was confidence.

Confidence that one sensor would normally be right.

Confidence that pilots would recognise unexpected stabiliser movement quickly.

Confidence that existing procedures were enough.

Confidence that keeping training differences small would not create new risk.

Confidence that delegated certification would catch anything serious.

Confidence that individually acceptable decisions would remain acceptable when combined.

Lion Air Flight 610 destroyed that confidence once.

Ethiopian Airlines Flight 302 destroyed it again.

The redesigned 737 MAX flying today has been subjected to modifications, training changes and scrutiny that the original aircraft never received. The FAA's relationship with Boeing has also changed, with direct regulatory involvement and oversight remaining substantially greater than before the crashes.

But the most important legacy of the MAX is not a piece of software.

It is the warning embedded in the chain of decisions that produced it.

Aviation became extraordinarily safe because it learned to assume that components fail, pilots become overloaded, sensors lie and organisations make mistakes. The moment a safety system begins depending on all of those things behaving exactly as expected, redundancy can become an illusion.

On two mornings separated by less than five months, that illusion collapsed.

Three hundred and forty-six people paid for it.

Previous
Previous

The Therac-25 Disaster Explained: How A Software Bug Gave Patients Massive Radiation Overdoses

Next
Next

The Rainbow Warrior Bombing Explained: Why French Secret Agents Blew Up A Greenpeace Ship