1장
When Nuclear War Hangs by a Thread
In the early hours of September 19, 1980, a simple maintenance procedure at a Titan II missile silo in Damascus, Arkansas turned catastrophic when a socket wrench slipped from Senior Airman David Powell's hand. The socket plummeted 70 feet before striking and puncturing the missile's fuel tank. Within hours, the leaking fuel would cause a massive explosion, launching the missile's 9-megaton nuclear warhead-equivalent to three times the explosive power of all bombs used in World War II-into a nearby field. This forgotten incident represents the closest America has come to accidental nuclear detonation on its own soil.
Eric Schlosser's "Command and Control" has been hailed by former Secretary of Defense William Perry as "essential reading for all Americans," while The New York Times called it "disquieting but fascinating." The book spent weeks on bestseller lists and was a finalist for the Pulitzer Prize. Its meticulous research reveals how America's nuclear arsenal-designed to protect against catastrophe-has repeatedly brought us to the brink of one. Through declassified documents and interviews with missile crew members, weapon designers, and military officials, Schlosser exposes the terrifying reality behind the systems controlling the world's deadliest weapons.
2장
The Delicate Balance of Nuclear Safety
The fundamental challenge of nuclear weapons control is captured in what experts call the "always/never dilemma"-nuclear weapons must always work when authorized but never detonate by accident or without proper authorization. This seemingly simple requirement has proven extraordinarily difficult to achieve.
When Bob Peurifoy joined Sandia National Laboratory in 1952, America's nuclear arsenal was dangerously primitive. Early bombs were essentially handcrafted devices requiring complex assembly procedures. The Mark 3 bomb was described as a "haywire contraption" with parts so poorly documented that one machinist had wrapped aluminum tubing around a Coke bottle during construction. Assembly initially took thirty-six men two weeks to complete. These early weapons were so delicate that batteries required frequent replacement, and plutonium cores would literally melt the explosive lenses if left assembled too long.
As the Cold War intensified, military demands for operational readiness frequently overrode safety concerns. Strategic Air Command (SAC), led by the legendary and uncompromising General Curtis LeMay, prioritized reliability over safety. When asked if his B-36 bomber might crash, LeMay famously replied, "It wouldn't dare." His training regime was notoriously demanding-"harder than war" according to one officer-creating a culture where mistakes were unforgivable. The unofficial SAC motto became: "To err is human, to forgive is not SAC policy."
This tension between military readiness and weapon safety created dangerous situations. When nuclear bombs began flying on airborne alert missions in 1958, the Air Force safety survey had bluntly concluded that "nuclear safety is not 'absolute,' it is nonexistent." For weapons requiring in-flight insertion of the nuclear capsule, there was a 15% probability of up to 40,000 pounds of nuclear yield in a crash. Yet SAC considered safety devices "operationally unsuitable" because they would "degrade reaction time to an unacceptable degree."
The consequences of this approach became apparent through a series of near-catastrophes. In 1958, a B-47 caught fire at Chennault Air Force Base with a Mark 39 hydrogen bomb aboard. In January 1961, a B-52 broke apart over Goldsboro, North Carolina, dropping two Mark 39 hydrogen bombs. One bomb's arming mechanisms activated during descent, and by the time it hit the ground, only a single low-voltage switch prevented a 4-megaton detonation that would have spread deadly fallout across Washington D.C., Baltimore, Philadelphia, and potentially New York City.
3장
The Human Element in Nuclear Command
While technological failures posed significant risks, human factors created equally dangerous scenarios. Fred Ikle, a Swiss-born scholar who studied nuclear risks at RAND Corporation, identified human error and psychological instability as major concerns. His classified report revealed that with approximately 20,000 Air Force personnel working with nuclear weapons-none requiring psychiatric screening-perhaps ten to twenty workers with access to nuclear weapons could be expected to have severe mental breakdowns yearly.
Ikle's "catalogue of derangement" included case histories of mentally unstable officers, including a paranoid schizophrenic captain who still flew bombers with "unimpaired proficiency." He warned that nuclear weapons might particularly attract those with paranoid delusions, poor impulse control, or infantile behavior patterns.
These concerns weren't merely theoretical. During the 1970s, military readiness declined precipitously. One-half to two-thirds of the Air Force's F-15 fighters were grounded due to maintenance issues, and the Strategic Air Command had lost more than half of its personnel since 1961. Illegal drug use soared throughout the military, with about 27% of all personnel using illegal substances. By the late 1970s, twenty-three security officers at missile sites had been stripped of their security clearances due to drug use.
Command and control systems proved equally vulnerable to human error. In November 1979, a technician at NORAD accidentally inserted a training tape into a computer, generating false warnings of a massive Soviet missile attack. The incident triggered Klaxons at SAC bases, sent bomber crews rushing to planes, and launched fighter-interceptors. Though quickly identified as false, the alarm revealed serious vulnerabilities in America's early warning systems.
An even more serious incident occurred on June 3, 1980, when National Security Adviser Zbigniew Brzezinski was awakened at 2:30 a.m. with news that 220 Soviet missiles were heading toward the United States. As he prepared to call President Carter, Brzezinski learned minutes later that early-warning radars and satellites hadn't detected any launches. The culprit was eventually identified: a defective forty-six-cent computer chip randomly inserting numbers into test messages.
4장
The Evolution of Nuclear Strategy
America's approach to nuclear weapons underwent dramatic transformations throughout the Cold War. After World War II, many military leaders initially supported international control of atomic weapons. General Spaatz openly supported world government, while even the anti-Communist General Groves argued that atomic bombs "should make war unthinkable" and favored international oversight.
However, as Cold War tensions emerged, America's nuclear strategy shifted toward deterrence through overwhelming force. By 1948, the Joint Chiefs approved HALFMOON, the first emergency war plan targeting the Soviet Union. The plan assumed America would initially lose ground battles in Europe before launching an "atomic blitz" involving 133 bombs targeting 70 Soviet cities-a "nation-killing concept" that President Truman initially rejected but later accepted during the Berlin Blockade crisis.
This strategy evolved into "massive retaliation" under President Eisenhower, who sought to deter Soviet aggression through the threat of overwhelming nuclear response. Secretary of State John Foster Dulles publicly announced that America would respond to aggression "by means and at places of our own choosing"-implying nuclear strikes against the Soviet homeland even for limited conflicts elsewhere.
By 1960, the Pentagon had created the Single Integrated Operational Plan (SIOP), America's first comprehensive nuclear war plan specifying when, how, and by whom every enemy target would be struck. The plan targeted 3,729 sites to be struck by 3,423 nuclear weapons across the Soviet Union, China, North Korea, and Eastern Europe. Conservative damage estimates projected killing 54% of the Soviet population and 16% of China's-roughly 220 million people-within three days.
When briefed on this plan, President Kennedy's science advisor Kistiakowsky expressed concern about "unnecessary and undesirable overkill" that could "kill 4 and 5 times over somebody who is already dead." Yet once launched, the SIOP could not be altered, slowed, or stopped.
Robert McNamara, Kennedy's Secretary of Defense, was deeply disturbed by the rigid nature of American nuclear strategy. After experiencing the Cuban Missile Crisis, where the world came perilously close to nuclear war, McNamara became increasingly concerned about accidental nuclear detonation. He cited aircraft crashes where "by the slightest margin of chance, literally the failure of two wires to cross, a nuclear explosion was averted."
5장
The Titan II: America's Deadliest Weapon
The Titan II represented the pinnacle of America's land-based nuclear deterrent. Standing 103 feet tall and 10 feet in diameter, it carried the W-53 warhead with a devastating yield of 9 megatons. The missile used dangerous "hypergolic" propellants-Aerozine-50 fuel and nitrogen tetroxide oxidizer-that ignited spontaneously when mixed, requiring personnel to wear specialized protective gear called Rocket Fuel Handler's Clothing Outfit (RFHCO) when working with them.
Despite its impressive capabilities, the Titan II system faced significant challenges. The missile's inertial guidance system was a technological marvel, using accelerometers, gyroscopes, and a small but powerful computer to calculate its position and trajectory. However, even slight calculation errors could cause a missile to miss by twenty miles.
By the late 1970s, the aging Titan II system was showing dangerous signs of deterioration. In Arkansas, airmen approached Senator David Pryor with concerns about the missiles' safety. A serious accident at Launch Complex 533-7 near Wichita, Kansas demonstrated these concerns when toxic oxidizer fumes filled a silo after maintenance work went wrong, resulting in casualties.
The investigation revealed that someone hadn't installed a filter inside the oxidizer line, possibly deliberately to make the work go faster. After the accident, the Air Force recommended using black vinyl electrical tape to seal protective suits at vulnerable points-a makeshift solution that highlighted the system's declining standards.
Despite carrying approximately one-third of America's total nuclear explosive force, the Titan II system was deteriorating while military readiness declined. Maintenance issues were widespread, with broken vapor detectors at most Arkansas silos. Meanwhile, illegal drug use among personnel created additional risks in a system that demanded perfect reliability.
6장
The Damascus Incident Unfolds
On September 18, 1980, around 6:30 PM, Senior Airman David Powell and Airman Jeffrey Plumb entered Launch Complex 374-7 near Damascus, Arkansas for routine maintenance. Powell was experienced, having served on a PTS (Propellant Transfer System) team for three years, while 19-year-old Plumb was still in training. Their task was addressing a low-pressure warning in the missile's oxidizer tank-a routine procedure.
Working two-thirds up the missile on a retractable platform, Powell attempted to unscrew the pressure cap using a ratchet from the wall instead of the required torque wrench-a common but unauthorized shortcut. When his nine-pound socket slipped off the wrench, it fell through the narrow gap between platform and missile, plummeted seventy feet, hit the thrust mount, and ricocheted into the missile's side. Immediately, fuel began spraying from the puncture "like water from a garden hose."
The situation quickly deteriorated. Water sprays meant to dilute fuel and extinguish potential fires created heat, causing oxidizer tank pressure to rise dangerously (reaching 18.8 psi from the normal 11.5), while the punctured fuel tank's pressure dropped to critical levels (2.6 psi). If the oxidizer tank ruptured or the fuel tank collapsed, the propellants could mix and cause a catastrophic explosion.
As the emergency developed, control center personnel struggled with conflicting warning indicators and emergency procedures. Captain Allan Childers plotted potential toxic corridors on a map while the command post assembled a Missile Potential Hazard Team of experts. However, they faced a scenario not covered by standard checklists.
After consulting SAC headquarters, Colonel John Moser ordered a complete evacuation. When asked about opening the silo door to dilute the fuel vapor with air, General Lloyd Leavitt at SAC headquarters adamantly refused-prioritizing containment of the fuel vapors and maintaining control of the thermonuclear warhead above all other considerations.
7장
Catastrophe and Aftermath
As the situation deteriorated, PTS Team B was dispatched to attempt to stabilize the missile in what would become one of the most harrowing nuclear accidents in American history. Breaking into the complex proved brutally difficult for airmen Greg Devlin and Rex Hukle, who struggled against the heavy steel door's electromagnetic lock system - a security measure designed to protect against intruders that now worked against them. Using pry bars and raw strength, they fought to create even the smallest opening. When they finally gained entry, their vapor detection equipment revealed an increasingly dangerous situation: 65 parts per million at the first door, climbing sharply to 181 ppm in the blast lock, and surging beyond 250 ppm at the second blast door - levels far exceeding safety parameters.
Despite safety advisors on site strongly recommending immediate withdrawal, Strategic Air Command headquarters, operating from the relative safety of their remote location, ordered them to continue the mission. The decision would prove catastrophic. When they managed to open the second door, they encountered what they described as a terrifying "steam room" of fuel vapor, with levels skyrocketing to an almost unbelievable 21,000 ppm - concentrations high enough to begin degrading their protective suits. The rubber components of their gear began to deteriorate almost immediately in the caustic environment.
After receiving belated orders to retreat, Airman David Livingston made the fateful decision to return to switch on a ventilation fan - a final attempt to reduce the deadly vapor concentration. Moments later, as he followed just a few feet behind Senior Airman Jeff Kennedy, the Titan II missile exploded with devastating force, creating a fireball visible for miles around and leaving a massive crater where the silo had been.
The explosion's force was so powerful it launched the 9-megaton warhead - with more explosive power than all bombs dropped in World War II combined - out of the silo like a cork from a bottle. The warhead, weighing several tons, landed remarkably intact in a ditch 200 yards away. Kennedy suffered multiple injuries, including a broken leg, when the blast wave threw him 150 feet through the air. Livingston, closer to the explosion's epicenter, sustained catastrophic injuries that would prove fatal despite desperate medical intervention.
The Air Force's response to the disaster proved nearly as troubling as the accident itself. Despite clear evidence of systemic failures, Air Force Secretary Hans Mark made the tone-deaf claim that "the Titan missile system is a perfectly safe system" even as emergency crews were still responding to the scene. The military's handling of the aftermath highlighted deep institutional problems: they maintained absolute secrecy about the nuclear warhead's status and location, actively impeded local emergency responders and authorities from accessing the site, and stubbornly clung to their "neither confirm nor deny" policy regarding nuclear weapons - even as local residents feared for their safety. This rigid adherence to secrecy protocols potentially endangered first responders who weren't given complete information about the hazards they faced.
The incident exposed profound failures not just in equipment maintenance and safety systems, but in the military's decision-making chain and emergency response protocols. The disaster would ultimately contribute to the acceleration of the Titan II missile system's decommissioning, though the Air Force would never fully acknowledge the extent of the near-catastrophe that occurred that night.
8장
The Legacy of Nuclear Close Calls
The Damascus accident represents just one of many nuclear close calls during the Cold War era, a period marked by numerous incidents that brought humanity perilously close to nuclear catastrophe. Sociologist Charles Perrow, who extensively studied dangerous technologies, identified nuclear weapons systems as "tightly coupled" and interactive systems-where multiple processes occur simultaneously and interact unpredictably. Such systems are characterized by their complexity, time-dependent operations, and rigid sequences that leave little room for deviation or error. These systems require standardized procedures and centralized control during routine operations but demand operator creativity and flexibility during emergencies-a paradoxical requirement that most military bureaucracies struggle to accommodate.
Stanford professor Scott Sagan's application of this "normal accident" theory to the Cuban Missile Crisis revealed disturbing patterns of near-catastrophes that challenged conventional historical narratives. While history books focus on Kennedy and Khrushchev's rational leadership, Sagan's research exposed numerous instances where control was more illusory than real. During the thirteen days of the crisis, an Atlas missile was test-launched from Vandenberg Air Force Base without Kennedy's knowledge or approval. In Turkey, nuclear weapons were loaded onto fighter planes with dangerously "loose" control protocols. Perhaps most alarming was the incident where a U-2 pilot accidentally strayed into Soviet airspace over Alaska, with American fighters authorized to use nuclear missiles against pursuing Soviet planes - a situation that could have rapidly escalated into nuclear conflict.
The Titan II explosion at Damascus perfectly exemplified Perrow's concept of a normal accident-triggered by a seemingly trivial event (a dropped socket) in a tightly coupled, interactive system. The system's overwhelming complexity meant officers were unable to determine exactly what was happening inside the silo, leading to dangerous speculation and improvised responses. Multiple warnings about potential dangers were ignored or minimized, unnecessary risks were taken in the name of following protocol, and crucial decisions were made by a commanding officer 500 miles away who lacked critical firsthand knowledge of the situation. The incident highlighted how organizational hierarchy and rigid procedures could actually increase rather than minimize risk in crisis situations.
Despite these inherent dangers and numerous close calls, America's nuclear safety record contains one remarkable statistic that deserves attention: none of the approximately 70,000 nuclear weapons built since 1945 has ever detonated accidentally or without proper authorization. This 99.99857% success rate reflects the dedicated efforts of countless military personnel, civilian contractors, engineers, and safety specialists who worked tirelessly to maintain nuclear security. However, when dealing with weapons of mass destruction, even this impressive record falls short of the required standard. Nuclear weapons demand 100% control and perfect performance, a standard that human imperfection and organizational limitations make nearly impossible to maintain indefinitely. Each close call serves as a sobering reminder of how thin the margin for error really is when dealing with humanity's most destructive technology.
9장
Nuclear Dangers in Today's World
While Cold War tensions have subsided, nuclear dangers persist and have evolved into new forms. Today, the United States maintains approximately 4,650 nuclear weapons: about 300 assigned to long-range bombers, 500 deployed on Minuteman III missiles, and 1,150 carried by Trident submarines. These submarines, constantly patrolling the oceans, form the most survivable leg of America's nuclear triad. Russia has about 1,740 deployed strategic weapons and perhaps 2,000 tactical weapons, with many aging systems being modernized despite economic constraints.
The greatest nuclear war risk now lies in South Asia, where geopolitical tensions combine with technological vulnerabilities. Pakistan and India are neighbors with bitter religious and territorial disputes over Kashmir, water rights, and cross-border terrorism, both possessing nuclear weapons with missile flight times as brief as four to five minutes. Neither has sufficiently hardened command-and-control facilities or reliable early warning systems, creating enormous first-strike pressure during crises. The short distances between major population centers make the situation particularly precarious.
Pakistan has doubled its arsenal since 2006 to approximately 100 weapons and continues to produce fissile material at an alarming rate. It remains the only nuclear arsenal entirely controlled by military leadership, which hasn't ruled out first use even against conventional attacks. This likely means tactical nuclear weapon authority has been delegated to lower-level field commanders, increasing risks of unauthorized use during conventional conflicts. Pakistan's development of battlefield nuclear weapons, including the short-range Nasr missile system, further blurs the line between conventional and nuclear warfare.
Rather than preventing conflict, nuclear weapons may have emboldened Pakistan to sponsor terrorism against India without fear of major retaliation, creating a dangerous form of nuclear blackmail. The countries have approached nuclear war roughly six times since the early 1990s, including during the Kargil War in 1999 and most recently after the 2008 Mumbai attacks, when India considered military strikes against terrorist camps in Pakistan.
The technical challenges of maintaining safe nuclear arsenals compound these geopolitical risks. As Eric Schlosser concludes in his extensive study of nuclear accidents, the absence of catastrophic nuclear accidents reflects less "good design than good fortune." The nuclear weapons systems that scientists and engineers struggled to make safer remain prone to "common-mode failures" where one problem can swiftly lead to many others - from computer glitches to human error to power failures. Recent near-misses, including a 2007 incident where six nuclear-armed cruise missiles were accidentally flown across the U.S., demonstrate continuing vulnerabilities. In the words of one retired SAC general, managing America's nuclear command-and-control system is like "holding an angry tiger by the tail" - and we can only hope our grip doesn't slip as new nuclear powers emerge and old systems age.
10장
The Ongoing Challenge of Nuclear Control
Today's nuclear landscape presents new challenges. While America's strategic weapons age, command-and-control mechanisms continue receiving upgrades. However, these systems remain vulnerable. In October 2010, a computer failure at F.E. Warren Air Force Base knocked fifty Minuteman III missiles offline for nearly an hour due to an improperly installed circuit card.
A 2013 Defense Science Board report warned that the system's susceptibility to large-scale cyber attacks had never been fully assessed. When questioned by Congress, Strategic Command's General Kehler admitted an "end-to-end comprehensive review" was still needed, acknowledging "we don't know what we don't know."
The contrast between offensive and defensive capabilities was stark during the 2011 raid that killed Osama bin Laden. Operation Neptune Spear demonstrated remarkable command-and-control coordination, with multiple military branches communicating in real time. Yet effectiveness in launching attacks reveals little about performance when under attack.
The 9/11 Commission Report provides a sobering example of command failure during a 78-minute attack. President Bush didn't board Air Force One until almost an hour after the first plane hit the World Trade Center. His calls to the Pentagon and White House bunker were repeatedly dropped. Vice President Cheney's order to shoot down hijacked airliners was never received by Air Force fighters. A system designed to handle thousands of nuclear weapons requiring presidential decisions within minutes proved incapable of managing an attack by four hijacked airplanes.
Launch Complex 374-7 was never rebuilt after the Damascus accident. Today, nature has reclaimed the site-grass-covered and surrounded by woods and farmland, with a large mound marking where the missile once stood. The only traces of what happened there are patches of concrete overgrown with weeds and scattered pieces of metal deformed by tremendous heat. Yet the legacy of Damascus remains-a stark reminder that our nuclear arsenal, designed to protect against catastrophe, has repeatedly brought us to the brink of one.