All cases
IP-0012Verified case record

Rocket Failures

Ariane 5 Flight 501

Europe’s new heavy-lift rocket was destroyed on its first flight after reused software encountered a value outside its original design envelope.

1996French GuianaLaunch Systems / Software
Ariane 5 Flight 501 archival case cover
Archive imageIP-0012
IndustryLaunch Systems / Software
Year1996
LocationKOUROU, FRENCH GUIANA
Failure typeInertial Reference Software Failure
Archive impact★★★★★
Human fatalities0
Engineering lessonRedundancy cannot protect a system when both channels share the same fault.

The knowledge that remained

Knowledge that outlived the failure.

  • 01

    Reused software must be revalidated against the new system’s complete operating envelope.

  • 02

    Two identical computers are not independent protection against a common software fault.

  • 03

    Representative end-to-end testing must include the real interfaces that can fail together.

Flight 501 became a defining case in software safety, common-mode redundancy, requirements validation, and the risks of reuse without full system-level testing.

Timeline

The sequence of failure.

  1. 01
    ConditionsJUN 04, 1996

    Ariane 5 launches

    Europe’s new heavy-lift launcher begins its maiden flight from Kourou.

  2. 02
    DecisionT+36 SECONDS

    Both inertial systems stop

    A sideways-velocity value overflows an unprotected 16-bit conversion in both computers.

  3. 03
    DecisionSECONDS LATER

    Diagnostic data becomes guidance

    The flight computer interprets the error pattern as valid attitude information and commands extreme nozzle movement.

  4. 04
    FailureT+39 SECONDS

    The launcher is destroyed

    Ariane veers, breaks apart under aerodynamic loads, and is destroyed by its safety system.

01 / What happened?

The event.

Ariane 5 Flight 501 was the first flight of Europe’s new heavy-lift launcher. Its inertial reference software included an alignment function inherited from Ariane 4 even though that function was no longer needed after liftoff.

The maiden flight and its payloads were lost less than a minute after launch, turning a software exception into a complete launch-system failure.

02 / Why did it fail?

The mechanism.

An unprotected 64-bit-to-16-bit conversion stopped both inertial reference systems and allowed diagnostic data to be interpreted as flight data.

Ariane 5’s horizontal velocity exceeded the Ariane 4 range. Converting that value from 64-bit floating point to a 16-bit signed integer caused both identical inertial systems to stop.

Sources & references

Trace the evidence.

Media rights record: The episode uses official ESA/CNES/Arianespace launch footage with institutional attribution; supporting public-domain and CC BY-SA assets are recorded in the production rights register.

Discovery edition

The case in under one minute.

The Short introduces the failure. This archive record preserves the mechanism, evidence, and engineering lesson beyond the video.

Ariane 5 Flight 501 episode coverShort ready for release

Editorial derivatives

Editions from this case.

01
Engineering Failure PDF

A portable, source-backed edition of the complete case.

Planned
02
Printable Timeline

The failure sequence formatted for print and classroom display.

Planned
03
Technical Infographic

Mechanism, consequence, and lesson in one visual system.

Planned
04
Teacher Pack

Discussion prompts, activities, and a structured answer guide.

Planned

The question to remember

Was Ariane 5 lost because of one bad number?

Answer

The overflow triggered the event, but the loss required a larger system failure: unnecessary reused code, identical redundancy, missing protection, and incomplete end-to-end testing.

Want to go deeper?

The Engineering Failure Library

Four source-backed cases, timelines, causal chains, prevention principles, and a cross-case pattern map in one numbered field guide.

Explore Volume 1