CSB Investigation — Ethane Cracking Furnace Explosion
Shell Polymers Furnace Explosion and Fire
Shell Polymers Monaca LLC
📍 Monaca, Pennsylvania
Incident Date: June 4, 2025  |  CSB Final Report Released: September 16, 2026
0
Fatalities
0
Injuries
$95M
Property Damage
Ethylene / Cracked Gas
Chemical / Hazard
📋 Incident Summary

On June 4, 2025, at approximately 2:19 p.m. local time, an explosion and fire occurred in Furnace 5 of the ethane cracking unit at the Shell Polymers Monaca facility in Monaca, Pennsylvania. The explosion severely damaged Furnace 5 and was followed by a fire, releasing an estimated 5,100 pounds of ethylene and combustion products. Fifteen employees evacuated the area. Shell estimated approximately $95 million in property damage. No fatalities or injuries were reported.

The Shell Polymers Monaca facility — a $6 billion petrochemical complex that began operations in 2022 — converts ethane to ethylene through a high-temperature cracking process in an ethane cracking unit containing seven furnaces. During normal operation, a solid carbon residue known as coke accumulates in coke traps designed to prevent the material from migrating downstream. In early 2025, during a planned unit outage, Shell discovered that the coke traps in all seven furnaces required cleaning — a task that had never been performed at the facility since its startup.

As Furnace 5 was being returned to service after its coke trap cleaning on June 3–4, 2025, a process control engineer inadvertently opened both motor-operated valves (MOVs) that had been isolating the furnace from the downstream cracked gas system. The process control engineer assigned to this task had never performed it before and had limited knowledge of the process. When both isolation valves were simultaneously opened, flammable cracked gas backflowed from the downstream quench tower through the unintended flow path into the furnace firebox, where it contacted lit pilot burners and ignited approximately six minutes later — causing the explosion that ruptured the firebox wall and triggered the subsequent fire.

Furnace 5 was repaired and returned to service approximately seven months after the incident. The CSB's final report, released September 16, 2026, found that despite Shell's process hazard analysis having previously identified cracked gas backflow as a potentially fatal hazard, the facility relied solely on administrative controls — specifically 11 procedure-based controls — rather than implementing engineered safeguards. Available engineered controls provided by the furnace technology licensor were not configured for use during the removal of double isolation.

🔎 Key Findings
Finding 1
Inexperienced Operator Assigned to Critical First-Time Task
The process control engineer who opened the furnace isolation valves had never performed this task before and had limited knowledge of the ethane cracking process. No minimum experience or qualification requirement governed who could perform this safety-critical valve operation.
Finding 2
Reliance on 11 Administrative Controls — No Engineered Safeguards
Shell identified cracked gas backflow as a potentially fatal hazard in its process hazard analysis but implemented only administrative controls to prevent it. All 11 controls required workers to correctly follow procedures. When one person made one error, every layer of protection failed simultaneously.
Finding 3
Licensor-Provided Engineered Controls Were Not Configured
The furnace technology licensor had provided engineered controls capable of preventing cracked gas backflow during double-isolation removal. Shell had not configured these controls for use during this mode of operation. Available protection was on the shelf — unused.
Finding 4
HMI Design Made Valves Difficult to Distinguish
The human-machine interface displayed three nearly identical motor-operated valves on a single logic screen. The valve identification tags differed primarily in their final digit. The confusing display contributed to the engineer inadvertently manipulating the wrong valve and creating the hazardous backflow path.
Finding 5
First-Ever Coke Trap Cleaning — No Prior Operating History
None of the seven furnace coke traps had ever been cleaned in the facility's history. The June 2025 return-to-service of Furnace 5 following coke trap cleaning was a genuinely novel operation with no established procedural baseline and no history of prior performance on which operators could draw.
Finding 6
Six Minutes Between Gas Backflow and Ignition
Approximately six minutes elapsed between the inadvertent valve opening and the explosion. Flammable cracked gas accumulated in the furnace firebox and ignited on contact with lit pilot burners. The six-minute window was insufficient for detection and corrective action given the absence of automated safeguards.
🔍 Root Causes
1
Inadvertent Simultaneous Opening of Both Furnace Isolation Valves
The direct cause of the explosion was the simultaneous opening of two motor-operated valves that isolated Furnace 5 from the downstream cracked gas system. The resulting unintended flow path allowed flammable cracked gas to backflow from the quench tower into a furnace containing lit pilot burners. A process control engineer with no prior experience on this task opened both valves in sequence, unaware of the hazardous backflow path this created.
2
Sole Reliance on Administrative Controls for a Potentially Catastrophic Hazard
Shell's process hazard analysis had identified cracked gas backflow as a potentially fatal hazard. Despite this finding, the facility implemented no engineered safeguards — only 11 administrative controls, all of which depended on workers performing procedures correctly. This reliance on procedure as the only safety layer meant that a single human error could — and did — defeat every protection simultaneously. The technology licensor had provided engineered controls for this hazard, but Shell had not configured them.
3
Assignment of Unqualified Personnel to a Safety-Critical Task
The process control engineer assigned to the furnace return-to-service task had never performed it and had limited process knowledge. No qualification standard or minimum experience requirement governed assignment to this critical operation. The first-ever coke trap cleaning return-to-service was a novel, high-consequence task that warranted experienced oversight — none was required or provided.
4
Human-Machine Interface Design Deficiencies
The HMI design presented three nearly identical valve controls on a single screen, differing primarily in their final identification digit. This poor interface design increased the probability of operator error — specifically the risk of manipulating the wrong valve — during a complex, novel operation performed by an inexperienced engineer under the pressure of an active unit restart. HMI design is a recognized process safety issue governed by ISA-101 and related standards.
☑ CSB Recommendations
→ Shell Polymers Monaca LLC (Recommendation 2025-05-I-PA-1)
Review the Shell Polymers Monaca ethane cracking unit process hazard analysis to identify process deviations that are addressed solely with administrative controls. Implement an inherently safer design or an engineered control for any scenario identified that could result in a fatality, serious injury, or substantial property damage.
→ Shell Polymers Monaca LLC (Recommendation 2025-05-I-PA-2)
Based on licensor input and good industry practices, such as ANSI/ISA-61511-2-2018 / IEC 61511-2:2016 (Functional Safety — Safety Instrumented Systems for the Process Industry Sector), implement and maintain an engineered control to prevent backflow of cracked gas into a furnace during all modes of furnace operation, including startup, shutdown, and maintenance return-to-service.
💡 Lessons Learned
Identifying a hazard in a PHA is not the same as controlling it. Shell's PHA correctly identified cracked gas backflow as potentially fatal. That finding obligated the facility to implement effective controls — not just to document the hazard and rely on procedures. A PHA finding that results only in administrative controls for a catastrophic scenario has not been acted on.
Eleven administrative controls are not stronger than one engineered safeguard. Multiple layers of procedure-based protection all share the same single point of failure: human error. When one person makes one mistake, every administrative layer can fail at once. Engineered controls work independently of human action — administrative controls do not.
Engineered controls provided by licensors must be configured and used. Shell had access to engineered controls specifically designed to prevent cracked gas backflow — provided by the technology licensor. These controls were not configured for use. Having a safeguard available but unconfigured provides zero protection.
First-ever operations demand heightened scrutiny and experienced oversight. The first-ever coke trap cleaning return-to-service was a genuinely novel operation. Novel high-consequence tasks require extra layers of review, experienced direct supervision, and explicit qualification standards for assigned personnel — not routine assignment to an inexperienced engineer.
HMI design is a process safety issue, not just a usability preference. A control interface that makes hazardous operations difficult to distinguish is a latent accident cause. HMI design should be evaluated in process hazard analyses and human factors reviews for any operation where valve confusion could create a dangerous flow path.
Engineered safeguards must cover all modes of operation. Many facilities implement safeguards for steady-state operation but leave non-routine modes — startup, shutdown, maintenance return-to-service — protected only by procedure. The Shell incident occurred during a non-routine return-to-service. OSHA 1910.119 requires that PHAs address all modes of operation.
PHA — (e) SOPs — (f) Training — (g) MOC — (l) PSI — (d)
🔨 Toolbox Talk
Topic: When Your PHA Finds a Fatal Hazard, What Happens Next?
Q:Your PHA identifies a scenario that could kill workers. The team writes it up as a finding. What controls do you put in place — and who decides?
Q:In this incident, Shell's PHA identified cracked gas backflow as potentially fatal and implemented 11 administrative controls. When one engineer opened the wrong valve, all 11 failed. What would have changed with one engineered safeguard?
Q:Does your PHA system distinguish between hazards that have engineered safeguards and those that rely solely on administrative controls? Who reviews that gap?
Q:Your facility is about to perform a non-routine operation for the first time. Who decides whether the assigned operator is qualified? What does "qualified" mean in writing?
Q:When was your HMI last reviewed for human factors — specifically for scenarios where confusing a control with a similar-looking one could create a hazardous flow path?
✅ Audit / Verification Actions
✓Review your last 5 PHA action items — are any findings addressed solely with administrative controls for scenarios rated catastrophic or critical? If yes, what is the plan to implement engineered safeguards?
✓Identify your most critical valve operations during non-routine modes (startup, shutdown, return-to-service). Verify written procedures exist and that assigned operators have prior demonstrated experience.
✓Confirm that all engineered safeguards specified by process technology licensors have been configured and are active — especially for non-routine operating modes.
✓Conduct a human factors review of your DCS/HMI screens for safety-critical valve operations. Are similar valves clearly differentiated? Could an operator confuse them under stress?
✓Confirm your MOC process captures first-ever operations as a change requiring full review — including hazard analysis, procedure development, operator qualification, and pre-startup safety review.
🔗 PSM Element Connections

The Shell Polymers incident is a case study in how PSM elements interact — and how gaps in multiple elements compound into a single catastrophic event. Here is how each failed element connects to 29 CFR 1910.119.

Process Hazard Analysis — (e)
The PHA correctly identified cracked gas backflow as a potentially fatal hazard but did not result in engineered safeguards. OSHA 1910.119(e) requires that PHAs be acted on — hazard findings must be addressed with appropriate safeguards, not only documented.
Learn: PHA Requirements under 1910.119 ↗
Operating Procedures — (f)
The return-to-service task following the first-ever coke trap cleaning was a novel, safety-critical operation. OSHA 1910.119(f) requires written procedures for all phases of operations, including non-routine modes. Administrative controls cannot substitute for engineered safeguards on catastrophic hazards.
Learn: Operating Procedure Requirements ↗
Training — (g)
The engineer assigned had never performed the task and had limited process knowledge. OSHA 1910.119(g) requires that operators be trained to understand the hazards specific to the tasks they perform. Qualification to perform a safety-critical operation must be verified before assignment.
Learn: Training Requirements ↗
Management of Change — (l)
The first-ever coke trap cleaning and associated return-to-service was a change from normal operating history. OSHA 1910.119(l) requires that changes to processes be reviewed for safety implications before implementation — including changes to operating procedures and modes of operation.
Learn: MOC Requirements ↗
Process Safety Information — (d)
HMI design documentation and licensor-provided safety system specifications are process safety information. Shell's HMI presented nearly identical valve controls in a confusing layout, and licensor-provided engineered controls were not configured. OSHA 1910.119(d) requires that process safety information be accurate and current.
Learn: PSI Requirements ↗
29 CFR 1910.119 Compliance & Process Safety Consulting
📋
132 CSB Case Studies
The most comprehensive incident library for PSM professionals. Every completed CSB investigation, analyzed through the lens of 29 CFR 1910.119.
Browse All Cases
📄
PSM Document Library
Ready-to-use PSM procedures, manuals, checklists, and templates — written by experienced process safety professionals, not templates.
View Library
🔍
PSM Program Assessment
Is your PHA finding closure process leaving catastrophic hazards protected only by administrative controls? Let us help you find and close the gaps.
Talk to Us
Process Safety Management Consulting & Compliance

SafeGuard PSM is a process safety consulting firm specializing in OSHA 29 CFR 1910.119 compliance. We work with chemical facilities, refineries, and industrial operators to build, improve, and audit PSM programs that protect workers and communities.

Our case study library covers every completed CSB investigation — analyzed through the lens of the 14 PSM elements so your team can learn from industry incidents and apply those lessons to your own facility.

Visit SafeGuard PSM ↗