On November 4, 2010, a Qantas Airbus A380 experienced a catastrophic engine failure shortly after takeoff from Singapore. Fragments from a turbine disk explosion tore through the aircraft's wings and fuselage, damaging critical systems including flight controls, fuel tanks, hydraulics, and pneumatics. The flight crew, facing numerous system failures and an uncertain aircraft condition, made critical decisions to safely land the massive plane. Despite challenges like landing gear issues, loss of braking power, and an engine that wouldn't shut down, they landed the aircraft without any injuries to the 469 passengers and crew.
The root cause was traced to an oil pipe with a slightly too-thin wall, manufactured within the number two engine. This seemingly minor defect originated from a series of questionable design choices, machining errors, and flawed assumptions about engine behavior. The problem persisted through multiple checks, ultimately leading to the near-disaster. The story of Qantas flight 32 highlights not only the dramatic emergency but also the advanced safety features of modern aviation.
◊◊◊
A new Airbus A380 in flight. (Pascal Le Segretain)
Introduced in 2007, the double-deck, four-engine A380 is the largest passenger aircraft globally. Despite its impressive size and passenger comfort, many airlines found it too large for their operational models. Analysts believe the A380 was designed for a market that had shifted by its entry into service, leading to limited production (254 units) and early retirement of some aircraft. While its fate is unfortunate given the immense effort and technology invested, this article focuses on a specific incident.
Qantas, Australia's flag carrier, was among the airlines that found the A380 suitable, ordering 12 aircraft. The incident involved VH-OQA, nicknamed Nancy-Bird Walton, the first A380 delivered to Qantas.

VH-OQA, the aircraft involved in the accident. (Andrei Dimofte)
On November 4, 2010, VH-OQA arrived in Singapore for a stopover on its London-to-Sydney route. The flight was nearly full, with 440 passengers and 29 crew members, including five pilots. This included a relief second officer, a captain undergoing a line check, and a senior check airman training the first check airman, making the cockpit unusually crowded.
Captain Richard Champion de Crespigny, a veteran with over 15,000 flight hours, was in command. The flight crew, comprising Captain de Crespigny, First Officer Matt Hicks, Second Officer Mark Johnson, Check Captain Harry Wubben, and Senior Check Captain David Evans, possessed a combined 140 years of aviation experience and 71,000 flight hours.
At 9:56 a.m. local time, Qantas flight 32 departed Singapore. As the A380 climbed through 7,000 feet, four minutes after takeoff, all systems appeared normal. Unbeknownst to the crew, a catastrophic failure was imminent.
◊◊◊
A Rolls-Royce Trent 900 engine. (Wikimedia user Tangopaso)
The Airbus A380 is powered by four Rolls-Royce RB211 Trent 900-series turbofan engines, each generating up to 84,000 lbf of thrust. These engines were developed in the UK and competed with the American-built GP7200.
To understand the incident, a brief explanation of the Trent 900's structure is necessary. Like most high-bypass jet engines, it has a fan, compressors (low pressure, intermediate pressure, and high pressure), a combustion chamber, and turbines. Air is compressed, mixed with fuel, and ignited in the combustion chamber. The resulting energy spins turbines, which power the compressors and the fan, generating thrust.

Locations of turbines and compressors on the Trent 900. (FAA)
The Trent 900 features LP, IP, and HP sections. The fan acts as the LP compressor. The HP and IP turbine sections each have a single-stage disk with blades that capture energy from hot gases, spinning the disk and driving the respective compressors via concentric shafts.

Cutaway of the IP turbine area, highlighting components. (ATSB)
The HP and IP turbine disks are supported by a common bearing assembly, the HP/IP bearing hub, which encircles the drive shafts. This hub contains a bearing chamber filled with pressurized oil to ensure smooth operation and prevent wear.
An oil feed pipe supplies oil to this chamber. The final segment of this pipe, welded in place, passes through a buffer space between the inner and outer sections of the hub and is known as the "stub pipe."

FAA video clip visualizing the HP/IP bearing assembly. (FAA)
Within minutes of takeoff, a crack in the oil feed stub pipe caused an oil leak into the buffer space. The high temperature in this space (365-375°C) caused the atomized oil spray to ignite.

FAA animation of the failure sequence. (FAA)
The fire expanded, breaching a seal at the forward end of the bearing hub. Pressurized air from the annulus gas path rushed in, intensifying the fire and breaching the rear seal. The resulting "blowtorch" effect impinged on the drive arm connecting the IP turbine disk to its shaft, causing it to fail under the intense heat.
This entire sequence, from oil leak to drive arm failure, occurred in less than a minute.

The turbine disk disintegrates. (ATSB)
With the drive arm broken, the IP turbine disk, no longer connected to the drive shaft, spun uncontrollably. Within four seconds, centrifugal forces exceeded the disk's material strength, causing it to fracture into multiple high-speed fragments.

Disk fragments caused extensive damage. (ATSB)
These fragments, possessing immense energy, cut through the engine casing and cowling. One fragment exited downward, while others traveled upward through the left wing, causing significant structural damage, severing wires, and impacting fuel tanks and hydraulic systems. Numerous smaller pieces also caused widespread damage.

The trajectories of the fragments. (ATSB)
Onboard, the crew heard two bangs, followed by a cascade of warnings on the Electronic Centralized Aircraft Monitoring (ECAM) system. The autothrust disconnected. Captain de Crespigny leveled the aircraft while the crew assessed the ECAM messages.
The first warning was "ENG 2 TURBINE OVERHEAT," followed by 34 more messages within 20 seconds. While the №2 engine was severely damaged, it was still rotating, leading to initial confusion. The crew reduced power to the damaged engine, which briefly triggered an "ENG 2 FIRE" warning.

ECAM display showing multiple warnings. (ATSB)
First Officer Hicks made a "pan-pan" call to air traffic control. The crew decided to shut down the engine, but an "ENG 2 FAIL" message appeared. Attempts to activate the fire extinguishers were partially successful, but confirmation lights did not illuminate. The ECAM alerts revealed extensive damage beyond the №2 engine.
Fragments had damaged the left wing fuel tank, the leading edge slat mechanism, and the aircraft's electrical system. Approximately 650 wires were severed, affecting numerous aircraft systems. Damage included impacts to the left wing structure, loss of green hydraulic pumps, degradation of the yellow hydraulic system, loss of AC power from engines 1 and 2, loss of functionality of leading edge slats, partial loss of spoilers and ailerons, degradation of control over remaining engines, loss of left wing landing gear brakes, disruption of the pneumatic system, and loss of fuel shutoff valves and the fuel jettison system.

Map of operational (green) and inoperative (red) flight control surfaces. (ATSB)
The loss of the green hydraulic system, though not breached, disabled its associated pumps. The A380's hydraulic system relies on green and yellow systems for left and right sides, respectively, with backup actuators for individual flight control surfaces. Despite damage to roll control surfaces (ailerons and spoilers), the aircraft's inherent redundancy allowed for continued maneuverability.
Initial hydraulic indications confused the crew, suggesting damage was confined to the left side. However, cross-referencing ECAM alerts with detailed system status pages confirmed the widespread failures.

Passenger photo showing turbine fragment exit holes in the wing. (ATSB)
Assessing the aircraft as controllable, the crew decided to remain airborne to address all ECAM procedures before landing, requesting a holding pattern. This process took approximately 30 minutes.
Meanwhile, cabin crew noted fuel leaking from the left wing. A passenger in the upper deck observed the fuel leak and two large holes in the left wing's upper surface via the in-flight entertainment system's tail camera feed. The pilots decided against turning off the feed, believing it would cause more alarm.
◊◊◊

Part of the turbine disk impacted a building on Batam Island. (ATSB/Posmetro newspaper)
On Batam Island, Indonesia, debris from the №2 engine, including a large portion of the turbine disk, fell into a populated area, damaging a building. Fortunately, no one was injured. Social media posts showing wreckage led to initial reports of a Qantas A380 crash.

Locals examine fallen engine cowling on Batam. (Reuters)
While the crew worked through ECAM procedures, fuel continued to leak from the left wing, creating a fuel imbalance. Despite ECAM instructions to transfer fuel, the crew prudently decided against it due to the leak and suspected damage to the fuel transfer system.
After 55 minutes, all ECAM messages were cleared. However, the aircraft was over 40 tons above its maximum landing weight, and the fuel jettison system was inoperative. The crew determined that landing immediately was necessary, despite the overweight condition and degraded braking capabilities.

Flight path of flight 32, including holding pattern. (ATSB)
Captain de Crespigny tasked the Check Captains with calculating the required landing distance using Airbus performance software. The software initially returned an error due to an excessive application of an "operational coefficient" for multiple system failures. Check Captain Evans corrected this by manually entering the actual landing weight, allowing the software to calculate a feasible landing distance on Singapore Changi Airport's 4,000-meter runways, with only 100 meters to spare.

Indonesian police with recovered aircraft debris. (AP)
Preparing for approach, the crew requested fire trucks due to the fuel leak and briefed the cabin crew for a potential runway overrun. Captain de Crespigny conducted manual control checks during the approach, noting sluggish controls due to degraded roll control. They opted to control airspeed using only engine 3, as it was least affected by system failures.
The landing gear deployment was problematic due to the loss of the green hydraulic system, requiring the use of a backup gravity drop system. Captain de Crespigny maintained a narrow airspeed band, narrowly avoiding a stall warning and a low energy alert.
Using the fly-by-wire system and remaining controls, de Crespigny landed flight 32 on runway 20C at 11:46 a.m., less than two hours after takeoff. Despite degraded braking and no reverse thrust on engine 2, the aircraft stopped with only 150 meters of runway remaining.

Firefighters foam the aircraft after its emergency landing. (Reuters)
Upon engine shutdown, the left main gear brakes overheated due to strain, causing four tires to deflate. Fuel leaks posed a fire risk. Loss of electrical power prevented the auxiliary power unit from engaging, leaving only emergency power and one functional VHF radio.

Passengers disembark from flight 32. (Richard de Crespigny)
Contacting fire services, the crew learned that engine №1 was still running due to inoperative fuel shutoff valves and inoperative fire extinguishers. Firefighters managed to cool the brakes with foam, averting a fire.
The crew debated evacuation but decided against it, citing risks associated with slide evacuations. Passengers were moved to the right side of the aircraft, and the crew arranged for boarding stairs using mobile phones.
Firefighters attempt to extinguish the still-running №1 engine. (Reuters)
After 50 minutes, boarding stairs arrived, and all 440 passengers disembarked safely over an hour. The №1 engine was eventually shut down by firefighters using foam, over three hours after landing.
◊◊◊

Visualization of the thin wall of the oil feed stub pipe. (ATSB)
The crew of flight 32 received widespread praise for their professionalism and skill. Captain de Crespigny personally assisted passengers, answering their questions and providing reassurance.
The aircraft's design, particularly its fly-by-wire system and ECAM, played a crucial role in managing the extensive failures. The A380's redundancy allowed the crew to maintain control despite significant damage.

Dark residue inside the fuel tank indicated a brief flash fire. (ATSB)
While the outcome was positive, investigators identified potential for greater disaster. Turbine fragments narrowly missed the passenger cabin, and a brief flash fire occurred inside the left wing fuel tank when a hot fragment contacted fuel vapors. Fortunately, the fuel temperature was too low to sustain combustion.

Severed wires in the wing leading edge. (ATSB)
Rolls-Royce and Airbus investigated the extent of the damage, which exceeded design expectations. The investigation focused on why the IP turbine disk oversped and burst.
Aircraft certification guidelines classify disk failure as a "hazardous" event requiring "extremely remote" probability. Regulations also mandate minimizing secondary failures, leading to features like the A380's redundant flight control hydraulics.

Officials inspect the damaged №2 engine. (Reuters)
While the A380's design largely contained the damage, the inability to cut fuel to the №1 engine was a notable deviation from safety expectations. Rolls-Royce had theorized that a disconnected IP turbine disk would not accelerate sufficiently to burst due to compressor stall and engine surge. However, in this case, the electronic engine control system's rapid response, while preventing a full surge, allowed sufficient airflow to overspeed the disk.
To prevent recurrence, Rolls-Royce implemented an IP turbine overspeed function in the engine control system.
◊◊◊

Construction of the oil feed stub pipe and fittings. (ATSB, annotations mine)
The investigation traced the initial oil leak to the oil feed stub pipe, which had a wall that was too thin. This defect resulted from an offset counter bore during manufacturing, leading to uneven wall thickness and premature fatigue failure after only 677 flights.

Design drawings for the stub pipe bores. (ATSB, annotations mine)
During the design phase, the stub pipe's position was defined relative to datum AA (the outer clearance hole). The counter bore was intended to be aligned with this datum within a tolerance of Ø 0.10 mm.

Interpretation of tolerance values. (ATSB, annotations mine)
Manufacturing process changes complicated alignment. The stub pipe's position was determined by the interference bore, which was still referenced to datum AA. However, the inner hub counter bore (datum M) was not directly referenced to datum AA, creating a potential misalignment.

Manufacturing stage drawings for the stub pipe. (ATSB, annotations mine)
During machining, the hub assembly could shift imperceptibly when reconfigured for drilling the inner hub counter bore. This shift caused the timing pin's recorded position (datum AA) to become offset from its actual location. Consequently, the inner hub counter bore and the stub pipe counter bore were drilled off-center.

Drilling sequence of the bores. (ATSB, annotations mine)
This offset resulted in one wall of the stub pipe being significantly thinner than specified, leading to its failure.

Offset in the drilled position of the inner hub counter bore. (ATSB)
Original design ensured adequate wall thickness through alignment with datum AA. The reworked manufacturing process and inadequate inspections failed to detect the resulting offset and thin wall.

Final product with a thin stub pipe wall. (ATSB)
Inspections, such as OP 230, focused on the stub pipe counter bore relative to datum M, providing no information about its position relative to the pipe itself. Visual inspection was also limited due to the welded-in pipe.
Another inspection, OP 70, occurred prior to OP 230 and...




