How One Engineer’s “LAZY” Safety Check Severed a Teenage Girl’s Legs

 

June 2nd, 2015. A Tuesday afternoon in Staffordshire, England. The sun was shining over Alton Towers Resort, one of the United Kingdom’s most popular theme parks, attracting 1.8 million visitors every season. Families queued for attractions. Children squealled with excitement, and teenagers dared each other to ride the park’s most extreme roller coasters.

Among those coasters was the Smiler, a steel monster that had opened just two years earlier in May 2013, boasting a world record 14 inversions that would turn riders upside down again and again at speeds reaching 85 km per hour. The roller coaster had cost the park $18 million to build, and its distinctive five-legged steel structure called the Marmalizer loomed over the midway like a twisted carnival attraction from a fever dream.

 The park sat on the former estate of the Earl of Shrewsbury, a sprawling property that had opened to the public back in 1860. By 1970, management had begun installing attractions to draw crowds. And on April 4th, 1980, the site officially became a theme park inspired by Walt Disney World Resort in Florida. Now, 35 years later, Alton Towers operated nine roller coasters and had become the leading amusement park in the United Kingdom.

 The town of Alton itself was tiny, just 1,226 people as of the 2011 census. But the theme park next door drew massive crowds from across England and beyond. Success brought pressure. Pressure to maximize capacity. Pressure to keep guests happy. Pressure to keep the rides running even when perhaps they shouldn’t be. The Smiler was built by Gerslau Amusement Rides, a German company that sold the design as an off-the-shelf model called the Infinity Coaster 1170.

 referring to its track length of 1,170 m, 3,839 ft of twisted steel. The layout was complex and aggressive. Riders experienced those 14 inversions as they navigated corkcrews, loops, and a particularly challenging element called a batwing, where the track twisted passengers upside down, briefly right side up, then upside down again before spitting them out in the direction they’d entered.

 The batwing consisted of two half corkcrews connected by half loops with a small upright section between the loops called the apex. The highest point of the element where for just a moment riders would be right side up before being flipped again. Each train consisted of four cars carrying 16 passengers total secured by heavy U-shaped steel restraints that locked down over their shoulders.

 The trains themselves weighed approximately three metric tons when empty. And when loaded with passengers, they became projectiles of considerable mass hurtling through the air at speeds up to 85 km per hour, 53 mph. The roller coaster featured two lift hills, inclined sections where a large chain in the center of the track pulled trains upward.

 The first was a conventional angled climb. The second was vertical, pulling trains straight up while passengers lay on their backs, staring at the sky. The roller coaster normally operated with four of its five trains running simultaneously, giving it a theoretical capacity of 1,200 passengers per hour, crucial for a park that saw thousands of guests daily during peak season.

 The marketing for the Smiler had followed Alton Towers tradition with the park announcing Secret Weapon 7 in April 2012, maintaining mystery until the actual name was confirmed in January 2013 after being discovered on leaked trademark filings. The name referred to a fictional machine called the Marmalizer, supposedly operated by a fictional research organization that used various means to force happiness on the world.

People who underwent treatment, rode the roller coaster, would smile whether they wanted to or not. The Marmalizer was realized as that massive five-legged structure containing theming elements and video screens with the roller coaster moving through, around, and over it. The ride safety system used block sections just like railways do to ensure that only one train occupied any section of track at a time.

 If a train failed to clear a block section, if it stopped where it shouldn’t or took too long to reach the next section, the system would automatically prevent the next train from entering that block. On a railway, a train would pass a red signal and the brakes would engage. But roller coaster trains don’t have brakes or drivers, so the stopping is achieved through elements built into the track.

 A block section either ends at the top of a lift hill where the train stops because the chain stops moving or track mounted brakes physically stop the train. This system had worked flawlessly thousands of times since the Smiler opened until June 2nd, 2015. The day was busy at Alton Towers. The weather was dry but windy, very windy.

 Wind speeds at the site reached 74 km per hour, 46 mph. This was well above the 55 km perph limit that Gestlau, the manufacturer, had specified as the maximum safe operating condition for the Smiler. Above that speed, the roller coaster was supposed to be shut down entirely. The wind could affect how trains moved through the layout, particularly on elements that required precise speed to complete successfully.

 But shutting down one of the park’s most popular attractions on a crowded Tuesday would mean disappointed guests, longer lines at other rides, complaints, and lost revenue. Management made a decision. Keep it running. Not only that, add the fifth train to increase capacity even further. Get those people through the queue faster, maximize throughput, keep the guests happy and the money flowing.

At 10:08 p.m., the roller coaster safety system reported a fault. The dispatcher, the head of the ride crew operating the attraction, called two maintenance engineers to investigate while passengers sat in a train at the station, unable to depart because the fault had caused the system to automatically stop all dispatches.

 This is exactly what safety systems are designed to do when something seems wrong, stop everything until it can be investigated. The engineers determined that the fault stemmed from a ride crew member holding the clear to start button on his console down for too long. It was a minor human error.

 Nothing mechanical, nothing dangerous. They entered it into the log book. As such, the waiting passengers were unloaded from their train by 1:10 p.m. and sent back out onto the midway. Train 5, which had been sitting on a parallel storage track, was moved closer to the station in preparation for being added to the operational fleet.

 The unloaded train departed the station empty at 1:13 p.m. for testing. Over the next several minutes, all four operational trains were cycled empty and brought back to the station. By 1:19 p.m., four empty trains sat in the station like a queue at a taxi stand. The control system was switched to maintenance mode to allow train 5 to be transferred onto the actual track where it joined the queue of emp

ty trains by 1:25 p.m. Now there were five trains on the track. Five trains, not four, five. This fact, simple, observable, crucial, would somehow get lost in the chaos of the next hour. Operations restarted at 1:29 p.m. with an empty train being dispatched for testing. According to Gestlau’s instructions, test trains should be loaded with water-filled dummies to simulate the weight of passengers, especially in high wind conditions where weight can make a critical difference in whether a train maintains enough speed to complete the layout. This was not done. The empty

train, significantly lighter than it would be with 16 passengers aboard, was sent out into winds that were already 19 km per hour over the safe operating limit. The train made it up the first liftill, dropped down, and raced through the first half of the layout. But when it reached the second liftill, the vertical section, something went wrong.

The train failed to engage with the chain. It sat there at the base of the vertical lift, motionless, occupying block three. The safety system immediately triggered an alert. A train had failed to clear its block section. Witnesses watched as four maintenance engineers assembled on the platform. Three of them headed out into the ride area to reach the stranded train while the fourth went to the control room.

When they reached the stuck train, they pushed it forward by hand until it engaged with the lift chain. The train then completed the layout without further issues and arrived back at the station by 1:40 p.m. creating a queue of five empty trains waiting in line. Everything seemed fine. The fault had been resolved.

 Time to resume normal operations and start loading passengers. Train 3. The designation Alton Towers used for this particular train was dispatched from the station empty at approximately 1:40 p.m. It climbed the first lift hill, the chain pulling it up to the highest point of the ride. At the crest, the train disconnected from the chain automatically and tipped forward, accelerating down the drop as gravity took over.

 It raced across the eastern section of the layout, picking up speed, passing both the maintenance building and the station with the control room visible below. The train entered the batwing element at speed, twisting through the first half corkcrew that turned it upside down, then climbing up the first half loop. This is where momentum becomes everything.

 The train needed sufficient speed to carry it up and over the apex, the highest point, and through the second half loop and corkcrew to exit the element. But train 3 was empty, no passenger weight, and it was fighting winds of 74 kmh. Winds that were supposed to have shut down the ride entirely.

 The train climbed the first half loop, reaching the apex at the top. It navigated partway through the second half loop, turning partially upside down as the track curved, and then it slowed. The combination of excessive wind resistance, lack of passenger weight, and the complex forces acting on the train as it moved through the inversions meant the train simply didn’t have enough energy to complete the element.

Physics took over. The train stopped, turned partially upside down near the top of the second loop. For a moment, it hung there, suspended. Then, gravity pulled it backward. The train rolled back down into the apex section, that small upright portion between the two half loops. It gathered speed rolling backward, climbed partway back up the first half loop, stopped again, and rolled forward.

 Back and forth it went, penduluming in the batwing like a ball bearing in a curved track. Each swing covering less distance as friction and air resistance bled away energy. Finally, after several oscillations, train 3 came to rest at the center of the apex, approximately 7 m off the ground, stuck between the two highest points of the element.

 The train had valied, a term used when roller coaster trains with insufficient momentum end up trapped in the valley between two peaks. The safety system immediately recognized the problem. Train 3 had failed to clear block three by reaching the final brakes ahead of the station. An error message appeared on the screens in the control room. block stop fault.

 The display showed train locations as four vehicles ground level, one vehicle top of lift one. This was accurate. Four trains sat at the station. One train, train 4, which had been loaded with passengers at 1:41 p.m. sat stopped at the top of the first lift hill. The system was doing exactly what it was designed to do, what it had been programmed to do, what safety regulations required it to do, preventing train 4 from entering block three.

 While train three still occupied that section of track, the 16 passengers in train 4 sat there, restrained and unable to move, suspended at the highest point of the first lift hill with a view across the entire park. They could see for miles. Some probably thought it was exciting this pause before the drop. Others might have wondered why they weren’t moving.

 Was this part of the ride? A deliberate pause to build tension or was something wrong? Minutes passed. They waited. The wind howled around them. Below maintenance engineers were dealing with what they thought was a familiar problem. One of the maintenance engineers headed out to a remote control panel labeled OPB3 located near the bottom of the second lift hill.

 This positioned him more than 75 m away from the batwing where train 3 sat stranded over 248 ft of linear distance. From his position, he couldn’t directly see the vali. He used the control panel to reset the block system, which automatically placed the roller coaster in maintenance mode. The error message disappeared from the screens. The system had been told essentially to forget what it knew about train occupancy and start fresh.

 The engineer walked back to the control room. Arriving by 1:49 p.m., he asked the dispatcher for a code zero, the internal code word for an evacuation via the station. The dispatcher, following protocol, asked the other maintenance engineers present if it was safe to put the roller coaster in evacuation mode at that point.

 Were all the trains accounted for? Was the track clear? Could they safely proceed with evacuating the passengers from train 4 and returning all trains to the station? The engineers confirmed it was safe. They looked around the control room area and station. They could see four trains at ground level in the station. They could see train four stopped at the top of the first lift hill.

 All five trains accounted for. In their minds, the track must be clear. The error must have been a false alarm, a ghost train, a software glitch they’d experienced before where the system incorrectly reported a blocked section after a previous error hadn’t fully cleared from memory. With confirmation given, the code zero was initiated at 1:50 p.m.

 placing the roller coaster in evacuation mode. This was a standard procedure used countless times before. Evacuation mode was designed to safely return all trains to the station so passengers could be unloaded and the ride could be reset. The system would automatically identify which trains were outside the station and bring them back in an orderly fashion.

 It was supposed to be foolproof, but it could only work with the information it had. And the information it had was catastrophically incomplete. When the system entered evacuation mode, it scanned for trains outside the station. It detected train 4 at the top of the first lift hill. It detected the four trains in the station. It did not detect train three in the batwing because train 3 wasn’t stopped on a liftill or on brakes.

 It was valied on open track and the system had no way to sense a train in that condition, especially after the block reset had erased all previous occupancy data. As far as the system knew, train 4 was the only train outside the station that needed to be recovered. The system calculated the recovery procedure for train 4.

 The train was stopped at the top of the first liftill. It couldn’t reverse back down the lift and returned to the station that way. The liftill only moved in one direction upward. The only way to return train 4 to the station was to complete the circuit, pull it over the crest of the liftill, release it, let it navigate the entire layout, and arrive back at the station the normal way.

 This was standard evacuation procedure for a train stopped on a liftill. The system prepared to execute. At 151 and 5 seconds p.m., the chain of the first liftill engaged. Train 4 began moving upward. The 16 passengers who had been sitting stationary for 10 minutes felt the motion resume. Finally, some of them probably cheered.

 They reached the crest of the liftill. That moment where the train tips forward and you see the drop ahead and your stomach does that little flip of anticipation. The train disconnected from the chain and tipped forward. Gravity took over. They accelerated down the first drop. Wind rushing past their faces. The first inversions approaching fast.

 This was it. This was what they’d waited in line for. The thrill, the speed, the 14 inversions, 26 seconds of screaming excitement. At 151 and 31 seconds PM, train 4 slammed into the back of the stationary train 3 at approximately 53 mph. The sound of the impact echoed across the park. Metal crushing metal. The horrific screech of steel grinding against steel.

 Screaming, immediate, piercing. The kind of screaming that comes from sudden, incomprehensible pain. Two maintenance engineers in the control room heard the crash and looked at each other. That sound wasn’t normal. That sound wasn’t supposed to happen. They headed out to investigate what had caused the noise, walking quickly at first, then breaking into a run when they heard the screaming.

 What they found when they reached the batwing was a scene from a nightmare. Two trains occupying the same piece of track, crushed together approximately 7 meters off the ground. Train four, the loaded train carrying 16 passengers, had accordioned into the back of train three, the empty train that had been sitting stationary in the apex of the batwing.

 The front of train 4 had compressed like a car in a head-on collision. The metal shield at the front of the lead car, designed to deflect wind and debris during normal operation, had folded inward from the impact, crushing and trapping the legs of the four passengers sitting in the front row. Those passengers were screaming. Others were crying.

 Some sat in shock, unable to process what had just happened. Blood was already dripping onto the concrete pit below. The impact had occurred with train 4 traveling at speed through the layout. The passengers had no warning. One second they were experiencing the thrill of the ride. The next they were being thrown forward against their restraints as their train violently decelerated from 53 mph to zero in a fraction of a second.

 The forces involved were enormous. The front row took the worst of it. Their legs trapped by folded metal, bones shattered, flesh crushed, but passengers throughout both trains suffered injuries. whiplash, broken bones, internal injuries from the sudden deceleration, and the restraints that held them in place even as their bodies tried to continue forward.

 The two maintenance engineers who had rushed to the scene stood there for a moment, stunned, trying to comprehend what they were looking at. Then training kicked in. They needed help, medical help, emergency services. They notified their superiors of the accident, but records would later show that emergency services weren’t called until 11 minutes after the collision, 11 minutes, nearly a quarter of an hour.

 While 16 people sat trapped in wreckage 7 m off the ground, some of them bleeding profusely from crushed legs, others going into shock, all of them terrified and in pain. 11 minutes before, someone picked up a phone and called 999. When ambulance crews finally arrived at Alton Towers, they faced an unprecedented challenge.

 The crash trains were 7 m, about 24 ft off the ground, sitting on a section of track inside a large fenced concrete pit. The entire roller coaster had been constructed below ground level due to local height restrictions that limited how tall structures could be above the surrounding terrain. This meant the ground level of the ride area was actually in a pit and accessing track that was 7 m up from the bottom of that pit required equipment.

 The first responders didn’t immediately have ladders, scaffolding, cutting tools. All of it had to be brought while injured passengers waited. The first responders who managed to reach the trains using ladders found themselves in an almost impossible situation. They were trying to provide medical care to severely injured patients who were sitting at extreme angles.

 The trains had come to rest tilted significantly to one side due to the impact. The patients were locked into massive U-shaped steel shoulder restraints that prevented access to most of their upper bodies. You couldn’t check for internal injuries. You couldn’t properly examine them. You couldn’t position them for treatment.

 and the patients in the front row had their legs trapped by folded metal that had compressed inward during the crash, crushing bone and tissue. One of the initial responders later described the scene as horrific, and mentioned the difficulty of trying to treat a patient several feet off the ground, sitting strongly leaned to one side with a massive locked restraint preventing access to or movement of most of the upper body.

 How do you stop bleeding when you can’t reach the wound? How do you stabilize a fracture when you can’t move the patient? How do you prevent shock when the patient is trapped in a position that’s compromising circulation? These were questions that had no good answers. The responders did what they could, but they were fighting physics and engineering as much as they were fighting the injuries themselves.

 Alton Tower’s maintenance crew began constructing scaffolding around the crash trains to ease access and create a stable platform for rescue workers. This took time, precious time. While they worked, fire department crews arrived with specialized cutting equipment. The front row passengers, four teenagers who had probably fought to get those coveted front seats, the best seats on any roller coaster, were trapped by metal that had folded inward like the crumple zone of a car.

 The fire department’s cutting tools, designed to cut through vehicle frames and building materials, struggled to get through the hardened steel beams that made up much of the roller coaster car’s structure, including the restraints. Cutting through the restraints risked injuring the passengers further if the tools slipped or if debris flew during cutting, but leaving them trapped meant they would continue bleeding, continue going deeper into shock, continue suffering.

 The rescuers made the only choice they could and began cutting. The sound of the cutting tools mixed with the crying and occasional screaming of the trapped passengers. Other riders who were less severely injured had been extracted earlier carried down ladders by rescue personnel once their restraints could be released normally. But the front row was different.

 The front row required cutting. It took over 4 hours to cut the final front row passenger free. 4 hours. Her name was not released to the media initially, but she was 17 years old, just a teenager out for a day at a theme park with friends or family, expecting thrills and fun, not lifealtering trauma.

 The medics who treated her at the scene later compared it to a miracle that she only lost a leg rather than dying from her injuries right there on the roller coaster. Her leg was so severely damaged, crushed so completely by the folded metal that amputation was the only option. But she was alive. She was conscious.

 She was going to survive even though her life would never be the same. In total, 11 of the 16 passengers required medical attention. Five were severely injured. Two would undergo leg amputations in the days following the accident. The others suffered broken bones, internal injuries, psychological trauma that would last far longer than any physical wound.

 The park was immediately closed and cleared of guests. Families who had been enjoying their day were ushered toward the exits, many of them not fully understanding what had happened. Some had heard the crash, others had seen emergency vehicles racing toward the Smiler. Rumors spread quickly through the crowd. A roller coaster had crashed.

 People were dead. The whole park was shutting down. Most of the rumors were wrong in their details, but the core truth was undeniable. Something terrible had happened. Investigators descended on the scene while the rescue effort was still underway. The rarity of a roller coaster accident this severe also gave rise to a flood of speculation, rumors, and outright false information.

 Some reports claimed a train had departed on its own without operator input. Others suggested a bug in the control system had applied the brakes of a train at a random point causing the collision. There were even suggestions of sabotage, of a planned attack, of terrorism. None of it was true.

 None of it even made sense given how roller coaster safety systems work. But sensational headlines sell papers and generate clicks. So, the misinformation spread. As investigators dug deeper into the accident and the events leading up to it, the truth became clear. This wasn’t a mechanical failure. This wasn’t a software bug. This wasn’t an attack.

 This was negligence. Multiple layers of negligence stacked one on top of another until the holes in the Swiss cheese model aligned perfectly and disaster became inevitable. The original error, the foundation upon which everything else was built, was the decision by Alton Towers to operate the Smiler during 74 km per hour winds.

 Justau the manufacturer had explicitly stated that the ride should not operate above 55 km per hour wind speed. This wasn’t a suggestion. This wasn’t a guideline. This was a hard limit imposed for safety reasons. Above that wind speed, the behavior of the trains becomes unpredictable. Empty trains especially can be affected by wind, potentially failing to complete elements that require precise speed.

 But it was a busy day at the park. Shutting down the Smiler, one of the most popular attractions, would mean disappointed guests. It would mean longer lines at other rides. It would mean people leaving the park unhappy, writing negative reviews, telling their friends not to visit. So, management made a decision, keep it running.

 Not only that, add the fifth train to maximize capacity, get people through the queue faster. The decision was made with full knowledge that wind speeds exceeded the manufacturer’s limits. This was not an oversight. This was a deliberate choice to prioritize throughput over safety. The ride crew also chose to go against Gerslau’s instructions in another critical way.

 When adding the fifth train to operations, they failed to inform the maintenance crew that they had done so. This seems like a minor communication failure, but it had catastrophic consequences. The maintenance crew spent the next hour operating under the assumption that four trains were in use when actually five were on the track.

 This meant that when they saw four trains at the station and one on the first lift hill, they believed they were seeing all the trains in operation. The missing train, train three valied in the batwing was invisible to them, not because they couldn’t physically see it, but because they weren’t looking for it. They thought all trains were accounted for.

The decision to send out a test train without loading it with water-filled dummies was another violation of manufacturer instructions. Gerslau specified that test trains should carry weight to simulate passengers, especially in high wind conditions. An empty train behaves very differently from a loaded train.

 It’s lighter, more susceptible to wind, more likely to lose speed on elements that climb against gravity. The test train that valied in the batwing might have successfully completed the element if it had been properly loaded with dummies. But it wasn’t. It was sent out empty into winds that were already over the operating limit to navigate a complex element that required precise speed to complete.

 The result was predictable to anyone who understood the physics involved. When that test train valied, the stage was set for disaster, but disaster wasn’t yet inevitable. There was still time, still opportunities to recognize the problem and prevent catastrophe. The safety system did its job perfectly. It detected the train stopped in block three and prevented train 4 from entering that block.

 An error message appeared on the control room screens. Block stop fault. At this point, proper procedure required the maintenance crew to physically verify the location of all trains before resetting the block system. They needed to check the surveillance cameras. They needed to walk the track if necessary. They needed to be absolutely certain they knew where every single train was before clearing that error and allowing operations to continue. But they didn’t do this.

 The Smiler was equipped with 25 surveillance cameras whose footage was displayed in the control room on multiple screens. Anyone in the control room had access to all the surveillance footage at any time, but employees later noted several critical floors in the system during the investigation.

 The images on two of the smaller screens were extremely small, making it difficult to see detail without getting up from the control desk and walking over to them. The order of the camera views could be switched around, making it difficult to keep track of which image showed which part of the roller coaster. Most critically, the positioning of the cameras was not ideal.

 Most of the valid train ended up hidden behind track support columns that were located closer to the cameras than the train itself. From most camera angles, you couldn’t see train three. The maintenance crew looked at the screens. They saw four trains at the station. They saw one train on the first lift hill. Five trains total, which is what they expected to see because wait, they expected to see four trains because they thought only four trains were operational.

 The ride crew hadn’t told them about adding train 5 to the operation. So, the maintenance crew counted four trains at the station and one on the lift hill and concluded that all trains were accounted for. They figured the error was a ghost train, a software glitch they had experienced before, where the system incorrectly reported a blocked section after a previous error hadn’t fully cleared from memory.

 This ghost train explanation had become something of a crutch, a catch-all excuse for error messages that didn’t make immediate sense. The system says block 3 is occupied, but we can see all our trains, so it must be a ghost train. Clear the error and move on. No need for extensive checking. No need to physically verify.

 just reset the system and get back to operations. This mindset, this assumption that error messages were often false positives, had been reinforced by past experiences with the surveillance equipment and the block system. False alarms had occurred before, equipment had been unreliable before. So, when faced with an error message that didn’t match their visual observation of the trains, they could see, they defaulted to assuming the error message was wrong.

 The engineer who went out to the remote control panel to reset the block system was operating more than 75 m away from the actual location of the valley train. He couldn’t see it from his position. He trusted that his colleagues had verified the track was clear. He performed the reset which cleared all occupancy data from the system and put the roller coaster in maintenance mode.

 Train 3, sitting stationary in the batwing was now invisible to the control system. As far as the computer knew, that trains simply didn’t exist anymore. The block section it occupied was now marked as clear. When the maintenance crew initiated the code zero and placed the system in evacuation mode, they believed they were following standard procedure.

Evacuation mode was designed to safely return trains to the station. It was supposed to be a controlled, methodical process. The dispatcher asked if it was safe to proceed. The maintenance engineers confirmed it was. They genuinely believed all trains were accounted for and the track was clear. They were wrong, but they didn’t know they were wrong.

 And the system couldn’t tell them they were wrong because they had just reset it and erased the information that would have told them they were wrong. The investigation later revealed a stunning lack of training among the maintenance engineers. Two of the engineers who conducted the reset of the block system had never been taught the procedures for properly resetting the block system.

 They had never even witnessed someone else performing a reset. They didn’t know that a thorough check of the supposedly occupied section was required before clearing the error. Training for maintenance engineers largely consisted of shadowing or accompanying a more experienced engineer, learning on the job through observation.

 But this training didn’t require any time spent handling ride breakdowns. It was theoretically possible for an engineer to be authorized to work on the Smiler, possibly even to work alone during a breakdown situation without ever having been trained on how to properly handle a breakdown. This meant that potentially an entire team of maintenance engineers could be working during a breakdown with none of them knowing the proper procedures.

 This is exactly what happened on June 2nd, 2015. The people tasked with resolving the block stop fault and ensuring the track was clear before resuming operations had never been trained on how to do so properly. They improvised based on their general knowledge of the ride and their past experiences with ghost trains and false alarms. They made assumptions.

 They skipped steps. They failed to verify and because of this they sent a loaded train full of passengers directly into a stationary train on the track ahead. The report later noted that insufficient crew structuring played a major role in the chain of events. When the system went into breakdown mode, the engineers failed to establish a leader within their group. Nobody took charge.

 Nobody said, “I am responsible for ensuring we do this correctly. Nobody assigned specific tasks and verified they were completed.” It also wasn’t common practice to formally establish the number of trains in operation before conducting procedures like a block system reset. This would have been as simple as referencing the day’s log book entries.

 Every train addition or removal was supposed to be logged, but they didn’t check the log book. They didn’t count the trains. They just assumed they knew how many were out there. When investigators interviewed the maintenance engineers and ride crew after the accident, they couldn’t get consistent answers about basic operational procedures.

 The engineers couldn’t agree on the rules about using maintenance mode or evacuation mode with passengers on board. The ride crew members couldn’t agree on how many empty test trains had to be cycled before passengers were allowed to board. There was no official number. The minimum was one test train. A maximum didn’t exist.

Different crew members had different ideas about what was required, which meant that operational procedures varied depending on who was working that day. This kind of inconsistency is a recipe for disaster in any safety critical system. The roller coaster’s control system had done exactly what it was supposed to do at every step.

 When train 3 valied, the system detected it and stopped train 4 to prevent a collision. When the maintenance crew reset the block system, the system cleared its memory as programmed. When evacuation mode was initiated, the system identified what it believed to be the furthest train from the station and began returning it as programmed.

 The system can’t know that it’s being operated by people with insufficient training. It can’t know that critical information about the number of operational trains wasn’t communicated. It can’t detect a train sitting on open track between brakes or lift hills. It can only work with the information it has.

 And the information it had after the reset was catastrophically incomplete. Once evacuation mode released train 4 from the top of the first lift hill, the collision became inevitable. Train 4 accelerated down the first drop, building speed. It raced through the first section of the layout, approaching the batwing at 53 mph. The passengers had no idea what was ahead.

The system had no way to detect the hazard. The maintenance crew believed the track was clear. 26 seconds after being released, train 4 entered the batwing and slammed into the back of train 3 with full force. Merlin Entertainment, the company that owns Alton Towers, closed three similar roller coasters at other parks immediately after the accident while protocols underwent evaluation.

 The health and safety executive served Merlin with a prohibition notice, banning the Smiler from reopening without express approval of improvements that would make a repeat impossible. The improvements took months. New guidelines were written. Training programs were completely overhauled with specific focus on breakdown handling procedures.

Maintenance engineers would now receive formal classroom instruction on block system resets, error interpretation, and track verification. The number of operational trains would be formally logged and communicated between ride crew and maintenance at the start of each shift. The surveillance camera system was upgraded with better positioning and clearer displays.

 Most importantly, the Smiler was fitted with an automated windsp speed measuring system that would shut down the ride automatically if manufacturer limits were exceeded, removing the human decision-making element that had led to operations continuing in unsafe conditions. The roller coaster eventually reopened in mid-March 2016, almost 9 months after the accident.

 The HSSE had reviewed and approved all changes. The ride crew and maintenance staff had been retrained. New procedures were in place, but the damage to Alton Tower’s reputation was severe. Attendance dropped significantly in the years following the accident. People who had visited the park for decades told reporters they would never return.

 The Smiler itself became notorious. Some vowed never to ride it again, while others were drawn to it specifically because of its dark history. The HSSE prosecuted Merlin Attractions Limited for their role in the accident. The company pleaded guilty to breaching the Health and Safety at Work Act. On September 27th, 2016, Merlin was sentenced to a fine of 5 million, approximately $8.

3 million US in 2023 terms. It was one of the largest fines ever imposed for a theme park safety violation in the United Kingdom. But for the victims and their families, no amount of money could undo what had happened. Two of the survivors, who each lost a leg in the accident, announced in September 2018 that they had filed lawsuits against Merlin Attractions Limited.

 Two more survivors announced plans to do the same. Their lawyers explained that the filing was necessary due to a three-year statute of limitations. The actual legal proceedings would take years due to the complexity of the case and the need for extensive medical documentation of long-term impacts. These weren’t just lawsuits about medical bills.

 These were lawsuits about lives permanently altered, careers ended before they could begin, chronic pain and disability, and psychological trauma that would last a lifetime. No ride operators or members of the maintenance crew appear to have been criminally charged for their roles in the accident. This was controversial.

Some felt that the individuals who made the decisions that directly led to the collision should face personal consequences. Others argued that the individuals were victims of a system that had failed to properly train them, that corporate policies and insufficient resources had set them up to fail. The maintenance crew made serious errors in judgment and failed to follow procedures that should have been second nature.

 But those procedures had never been properly taught to them, and the corporate culture at Alton Towers had apparently normalized taking shortcuts and making assumptions. After the accident, there were demands that the Smiler should be permanently closed or even demolished. The ride had severely injured people.

 It had traumatized dozens, but these demands missed the point. The Smiler isn’t an unsafe roller coaster. The ride itself was and is built to modern safety standards. The accident wasn’t caused by a design flaw or manufacturing defect. It was caused by humans making catastrophically bad decisions, operating in excessive wind, failing to properly load test trains, not communicating train counts, not verifying track clearance before resetting the block system, not properly training staff. Every single failure was

human, not mechanical. Alton Towers did make some changes to the Smiler’s theming after the accident. Various elements and video clips referencing correction and treatment were removed as these terms took on a darker meaning after people had been genuinely hurt. But the name remained, the Marmalizer structure remained, the logo remained.

The park evidently calculated that completely rebranding the ride would draw even more attention to the accident. The Smiler continues to operate as of 2024. It still holds the world record for most inversions on a roller coaster. It still draws long lines of thrillsekers. For many visitors, the accident is distant history, something they vaguely remember hearing about years ago.

 For others, especially those who were at the park that day or who followed the news coverage closely, the Smiler remains a symbol of corporate negligence and the dangers of prioritizing profits over safety. Roller coaster accidents where someone is seriously injured are extremely rare. Statistically, you’re far more likely to be injured in a car accident on the way to the theme park than on a roller coaster once you arrive.

 Modern roller coasters are engineered with multiple redundant safety systems. They’re inspected regularly. They’re maintained constantly. When accidents do occur, they almost always involve human error, someone bypassing a safety system, someone failing to follow procedures, someone making a bad judgment call. The Smiler accident fits this pattern perfectly. Every safety system worked.

Every warning was given, but humans ignored the warnings, bypassed the systems, and created the conditions for disaster. The 16 passengers who boarded train 4 that Tuesday afternoon had no reason to suspect anything was wrong. They’d waited in line like everyone else. They’d watched other trains depart and return safely.

 They’d strapped themselves in and prepared for an exciting ride. They had families waiting for them. They had futures ahead of them. 17-year-old Leah Washington was looking forward to the rest of her summer. 19-year-old Vicky Balch had her whole life planned out. Neither of them knew that in less than two minutes they would lose their legs.

 Not because of a mechanical failure, not because of a design flaw, but because wind speed limits were ignored, because maintenance crews weren’t properly trained, because nobody verified the track was clear. Four legs lost. The exact compensation amounts paid to Leah and Vicki were never fully disclosed. But no amount of money, whether hundreds of thousands or millions of pounds, could ever compensate for what was taken in those 26 seconds.

 No settlement can buy back a leg. The trust these passengers placed in Alton Towers was betrayed. Not by the machinery, not by the engineering, but by humans who decided operational efficiency mattered more than safety. So here’s the question. After hearing this story, would you still board a roller coaster without hesitation? Would you take your friends, your children, and trust that every single employee followed every single procedure correctly that day? Can you guarantee this will never happen again at any theme park anywhere in the world? Leave

your answer in the comments.

 

Disclaimer: This story is fictional and created for entertainment purposes only. Any names, characters, places, or events are fictitious or used fictitiously. No real person or organization is intended to be portrayed.

Recommended for You

View Archive arrow_forward