Pressure Safety in Secondary Refrigerant Loops: Four Near-Miss Incident Reports
Incident 1: Hangtian *** — Pressure Excursion from 3 to 8 Bar
(Note: The full name of the company should be omitted as required by the confidentiality agreement.)
Sequence of Events
- 08:15 System startup after weekend shutdown. Coolant loop at ambient temperature (22°C). Expansion tank bladder pressure checked — 1.5 bar(g), normal.
- 08:22 Chiller started. Coolant temperature begins dropping toward setpoint of -30°C. Flow rate stable at 45 L/min.
- 08:30 Coolant temperature reaches -15°C. System pressure at pump discharge: 3.2 bar(g). Normal for this temperature.
- 08:42 Operator notices pressure gauge reading 4.5 bar(g). No alarm triggered. Operator assumes gauge is faulty. Continues monitoring.
- 08:44 Pressure reaches 6.8 bar(g). High-pressure alarm triggers. Operator begins manual shutdown of chiller.
- 08:45 Pressure peaks at 8.1 bar(g). Relief valve (set at 8 bar) lifts. Coolant discharges to containment pit. Pressure drops to 5 bar(g) over 30 seconds as relief valve reseats.
- 08:50 System secured. Investigation begins.
Root Cause Analysis
The expansion tank bladder had failed. Not catastrophically — there was no visible rupture. The bladder had developed a slow nitrogen leak through a pinhole at the base of the bladder neck, where it clamped to the tank flange. The leak rate was small enough that the bladder pressure held at 1.5 bar(g) during the weekend shutdown. But when the coolant temperature dropped and the fluid contracted, the bladder was supposed to expand to compensate for the volume change. It couldn’t. The nitrogen had leaked out over the previous weeks of operation. The bladder was flat against the tank wall. The expansion tank was effectively a solid vessel with no gas cushion.
When the coolant temperature dropped from 22°C to -15°C, the coolant contracted by approximately 2.5% of its volume. In a properly functioning system, the expansion tank bladder would have expanded to accommodate this contraction. With the bladder failed, the contraction created a partial vacuum in the system. The pump, sensing the drop in suction pressure, cavitated briefly. The cavitation introduced vapor into the loop. When the vapor reached the chiller evaporator and condensed back to liquid, the volume collapsed. The collapsing vapor volume created a pressure spike that propagated through the loop. The spike was amplified by the water hammer effect at the elbows and tees in the piping. The result was a pressure excursion from 3 bar to 8 bar in under 30 seconds.
The relief valve worked as designed. It lifted at 8 bar(g) and reseated when the pressure dropped. The containment pit captured the discharged coolant. The system was designed with adequate overpressure protection. But the underlying failure — the bladder leak — had been developing for weeks. The system had no instrumentation to detect bladder integrity. The only indication of bladder health was the quarterly manual pressure check. The bladder had been checked in January and was fine. By March, it had failed. Two months of undetected degradation.
The pressure excursion was caused by a failed expansion tank bladder. The bladder failure allowed a partial vacuum to form during coolant contraction. Pump cavitation introduced vapor into the loop. Vapor condensation created a water hammer pressure spike. The relief valve functioned correctly, preventing a piping rupture.
Expansion tank bladder integrity is a safety-critical parameter in closed-loop secondary refrigerant systems. A failed bladder converts the expansion tank from a pressure-management device into a rigid vessel. Under thermal contraction, the system can develop a partial vacuum. Under thermal expansion, the system can overpressure. Both conditions are dangerous. Quarterly manual pressure checks are insufficient for detecting slow bladder leaks. Continuous bladder pressure monitoring is recommended for all systems operating below 0°C.
3 Consider a dual-bladder expansion tank design for critical systems. If one bladder fails, the second provides redundancy. The cost increment is approximately 30% over a single-bladder tank.
Incident 2: Da*** Pharma — Reactor Jacket Bulging Under Thermal Expansion
(Note: The full name of the company should be omitted as required by the confidentiality agreement.)
Sequence of Events
- 14:00 Batch process completed. Reactor temperature at 95°C. Coolant (LM-11C) at 90°C in the jacket. Operator begins cooldown procedure.
- 14:05 Operator closes coolant supply and return valves at the reactor jacket nozzles. Standard procedure — the TCU is shared between two reactors, and the operator needs to switch cooling to the second reactor.
- 14:06 Coolant trapped in the jacket between the two closed block valves. Volume: approximately 180 liters of LM-11C at 90°C. The jacket is now a sealed, liquid-filled vessel with no pressure relief path.
- 14:20 Second reactor batch begins. The TCU is now providing cooling to the second reactor. The first reactor is idle, waiting for the next batch.
- 14:55 Steam cleaning cycle initiated on the first reactor. Steam at 3 bar(g), 143°C, introduced to the reactor vessel — not the jacket. The jacket, still full of trapped LM-11C at 90°C, begins absorbing heat from the reactor vessel through the glass lining.
- 15:10 Coolant temperature in the jacket rises from 90°C to approximately 125°C. Thermal expansion of the LM-11C: approximately 4.5% by volume. The jacket is rigid. The fluid is incompressible. The pressure rises.
- 15:12 Operator hears a loud metallic “ping” from the reactor area. Steam cleaning is stopped. Inspection reveals the jacket has bulged outward at the cylindrical section. The glass lining on the interior of the reactor vessel is cracked at two locations corresponding to the jacket bulge points.
Root Cause Analysis
The root cause was thermal expansion of trapped liquid in a confined volume. The jacket was isolated by two closed block valves. The valves were closed as part of a standard operating procedure that had been in use for three years. The procedure had never caused a problem before because the previous coolant was a water-based fluid (LM-4) that was always drained from the jacket before the reactor was steam-cleaned. When the plant switched to LM-11C — a water-free fluid — the draining step was omitted from the revised procedure. The water-free fluid was supposed to be “permanent” — no need to drain and refill between batches. The procedure writer didn’t consider that the fluid would still be in the jacket when the reactor was steam-cleaned.
The thermal expansion of LM-11C from 90°C to 125°C is approximately 4.5% by volume. For 180 liters of trapped fluid, that’s 8.1 liters of expansion. In a rigid jacket with no pressure relief, the pressure generated by thermal expansion of a liquid is enormous — the bulk modulus of LM-11C is approximately 1.5 GPa. A 4.5% volume expansion against that bulk modulus generates a theoretical pressure of about 675 bar. The jacket didn’t reach 675 bar. It yielded at a much lower pressure — probably around 15-20 bar, based on the jacket wall thickness and material properties. The jacket bulging was the pressure relief mechanism. It was a destructive one.
The reactor jacket bulged because LM-11C coolant was trapped between two closed block valves and subsequently heated by a steam cleaning cycle on the adjacent reactor vessel. Thermal expansion of the trapped liquid generated pressure sufficient to yield the jacket wall. The procedure for switching to a water-free coolant did not account for the fact that the fluid remains in the jacket during reactor cleaning operations.
Any section of a coolant loop that can be isolated by closing valves on both ends must have a pressure relief device. This is a fundamental requirement of ASME B31.3 and is not specific to coolant systems. Thermal expansion of trapped liquid can generate pressures far exceeding the design pressure of any practical piping or vessel. A thermal relief valve — even a small one, 1/2″ or 3/4″ — is sufficient to prevent this failure mode. The cost of a thermal relief valve is approximately 500 yuan. The cost of the reactor jacket repair was 350,000 yuan. The ratio is 700:1.
3 When switching from water-based to water-free coolant, conduct a process hazard analysis (PHA) that specifically examines thermal expansion scenarios. Water-free fluids have different thermal expansion coefficients than water-based fluids. The PHA for the water-based system may not be valid for the water-free system.
Incident 3: Zhejiang — LM-4 System Pressure Approaching Critical
Sequence of Events
- 10:30 System operating in heating mode. LM-4 circulating at 140°C. System pressure: 3.5 bar(g). Normal for this temperature — the vapor pressure of water at 140°C is approximately 2.6 bar(a), plus the nitrogen blanket pressure in the expansion tank.
- 10:42 TCU controller malfunction. The heating output fails to modulate. The electric heater continues at full power. The temperature controller setpoint is 140°C. The actual temperature begins rising above setpoint.
- 10:48 Coolant temperature reaches 155°C. High-temperature alarm triggers. Operator acknowledges alarm but does not immediately shut down the heater — the alarm has triggered falsely before, and the operator wants to confirm the reading.
- 10:51 Coolant temperature reaches 168°C. Pressure now at 7.8 bar(g). Operator initiates emergency shutdown of the heater.
- 10:53 Heater element remains hot due to thermal inertia. Coolant temperature continues to rise — reaches 178°C. Pressure at 12.2 bar(g). The water component of LM-4 is approaching its boiling point at this pressure. The coolant is not boiling yet, but the margin is narrowing.
- 10:56 Coolant temperature peaks at 184°C. Pressure peaks at 18.5 bar(g). The design pressure of the system is 20 bar(g). The margin between operating pressure and design pressure is 1.5 bar — approximately 7.5% of the design pressure. No safety margin for instrument error.
- 11:05 Heater cools down. Temperature and pressure begin to drop. System returns to normal by 11:30.
Root Cause Analysis
The immediate cause was a TCU controller failure — the heating output failed in the full-on position. But the controller failure alone wouldn’t have created a near-critical pressure situation. The deeper issue was the system’s pressure-temperature relationship and the lack of an independent high-pressure shutdown.
LM-4 is a water-based coolant. At temperatures above 150°C, the water component begins to develop significant vapor pressure. The system pressure is the sum of the nitrogen blanket pressure and the vapor pressure of the coolant. At 184°C, the vapor pressure of water is approximately 11 bar(a). Adding the nitrogen blanket pressure, the total system pressure approached 18.5 bar(g). The system design pressure was 20 bar(g). The margin at the peak temperature was 1.5 bar. That’s not a margin. That’s a rounding error.
The system had a high-temperature alarm. It did not have a high-pressure alarm. It did not have an independent high-pressure shutdown. The operator was the only defense against a pressure excursion, and the operator was relying on a temperature reading that had a history of false alarms. The system was one instrument failure away from a pressure relief event — or worse, a piping rupture.
The system pressure approached 18.5 bar(g) — 92.5% of the design pressure — due to a TCU controller failure that caused a coolant temperature excursion to 184°C. The system lacked an independent high-pressure alarm and shutdown. The operator’s delayed response to the high-temperature alarm reduced the available safety margin. The water vapor pressure in LM-4 at elevated temperatures is the dominant contributor to system pressure and must be accounted for in the pressure safety design.
Water-based secondary refrigerants operating above 150°C require a pressure-based safety system in addition to a temperature-based safety system. The pressure-temperature relationship of water is non-linear. Between 150°C and 184°C, the vapor pressure increases from approximately 4.8 bar(a) to 11 bar(a) — a 2.3x increase over a 34°C temperature rise. A temperature alarm alone may not provide sufficient warning time. A high-pressure alarm and independent high-pressure shutdown are essential for systems operating in this temperature range.
3 Implement a “two-out-of-three” voting logic for high-temperature alarms. A single sensor with a history of false alarms undermines operator trust in the alarm system. Two independent sensors with a voting logic reduce false alarms while maintaining protection.
Incident 4: Chongqing Changyu — LM-15B Boiling at 106°C
(Note: The full name of the company should be omitted as required by the confidentiality agreement.)
Sequence of Events
- 09:00 System startup. LM-15B circulating at ambient temperature. Heater started. Temperature setpoint: 150°C. System pressure: atmospheric (vented expansion tank — open system design).
- 09:45 Coolant temperature reaches 106°C. Operator notices fluid level in the expansion tank rising rapidly. Then the expansion tank vent begins discharging vapor. The fluid is boiling.
- 09:47 Operator shuts down the heater. Boiling continues for approximately 3 minutes as the heater elements cool down. Total fluid loss: approximately 80 liters out of the 300-liter charge.
- 10:15 System secured. Fluid sample taken from the expansion tank. Sample sent to lab for analysis.
Root Cause Analysis
The lab results were definitive. The LM-15B had been contaminated with a low-boiling solvent — methyl ethyl ketone (MEK), boiling point 79.6°C. The MEK was a process solvent used in the reactor. A pinhole leak in the reactor’s internal heating coil had allowed MEK to diffuse into the coolant loop over a period of several weeks. The MEK dissolved in the LM-15B. At low temperatures, the mixture behaved normally. But as the temperature approached the boiling point of MEK, the MEK began to vaporize. The vapor bubbles nucleated boiling in the LM-15B at a temperature far below its normal boiling point.
The concentration of MEK in the LM-15B was approximately 8% by volume. At 8% concentration, the mixture’s bubble point — the temperature at which the first vapor bubble forms — was approximately 104°C. The system was being heated to 150°C. The boiling started at 106°C, which is consistent with a mixture bubble point of 104°C plus a small amount of superheat required for nucleation.
The pinhole leak in the heating coil had been present for at least six weeks. The operators had noticed a gradual increase in the expansion tank level — the MEK was adding volume to the system — but they attributed it to thermal expansion of the LM-15B. The level increase was small — about 2% per week — and within the range of normal expansion for a system cycling between ambient and 150°C. The operators didn’t recognize it as a sign of contamination.
LM-15B boiled at 106°C — 54°C below its rated maximum temperature — due to contamination with MEK solvent from a pinhole leak in the reactor heating coil. The MEK reduced the mixture’s bubble point to approximately 104°C. The boiling was not a fluid failure. It was a process contamination event. The LM-15B was performing correctly for a contaminated fluid. The root cause was the undetected coil leak.
Heat transfer oils are susceptible to boiling point depression when contaminated with low-boiling solvents. A fluid rated for 160°C can boil at 106°C if contaminated with a solvent that has a boiling point of 80°C. The contamination may not be obvious. The solvent dissolves in the oil. The mixture looks normal. The viscosity may be slightly lower than expected, but the difference is small. The only reliable detection method is periodic gas chromatography analysis of the heat transfer fluid. If your heat transfer oil system is connected to a process that uses volatile solvents, test the oil quarterly for solvent contamination. An unexplained increase in expansion tank level is a warning sign. Don’t ignore it.
3 Pressure-test reactor heating coils annually. A pinhole leak that allows solvent diffusion may not be detectable by a standard hydrostatic test at ambient temperature. Consider a helium leak test for critical applications. The cost of a helium leak test is approximately 5,000 yuan. The cost of the fluid loss and downtime in this incident was approximately 25,000 yuan — and that was a relatively small system.
Cross-Incident Analysis
Four incidents. Four different pressure-related failure modes. But they share common threads.
First: three of the four incidents involved a failure of pressure management — an expansion tank bladder that leaked, a jacket that had no pressure relief, a system that had no high-pressure shutdown. The pressure in a secondary refrigerant loop is not a fixed parameter. It’s a dynamic variable that responds to temperature, flow, and system integrity. Treating it as a fixed parameter — something you set once and forget — is how these incidents happen.
Second: all four incidents involved a gap between the system design and the operating reality. The bladder was checked quarterly, but it failed in two months. The jacket isolation procedure was written for water-based coolant, but the system had been switched to water-free. The temperature alarm was supposed to protect against pressure excursions, but the operator had learned to ignore it. The heat transfer oil was rated for 160°C, but nobody tested it for solvent contamination. In every case, the system was designed correctly for the conditions the designers imagined. The problem was that the actual conditions were different from the imagined ones.
Third: the cost of prevention was, in every case, a fraction of the cost of the incident. A continuous bladder pressure monitor: 2,000 yuan. A thermal relief valve: 500 yuan. A high-pressure shutdown switch: 3,000 yuan. A quarterly GC analysis: 1,500 yuan per year. The total cost of implementing all four recommendations across all four systems would have been less than 50,000 yuan. The total cost of the four incidents exceeded 500,000 yuan. The ratio is 10:1. And that’s not counting the production losses, the reputational damage, or the near-miss with a reactor jacket that could have ruptured.
Pressure safety in secondary refrigerant systems is not complicated. It’s not expensive. It’s just easy to overlook. Until it isn’t.
Post time: Aug-26-2026




