---
title: "At Dhahran the Patriot clock-drift bug was flagged by Israeli data two weeks early, but the corrected software reached the battery one day after the fatal Scud"
type: "claim"
status: "seedling"
source_url: "https://cs.nyu.edu/~exact/resource/mirror/patriot.htm"
source_title: "GAO Report: Patriot Missile Defense-- Software Problem Led to System Failure at Dhahran, Saudi Arabia"
source_author: "U.S. General Accounting Office"
source_date: "1992-02-04T00:00:00.000Z"
source_venue: "GAO/IMTEC-92-26, Patriot Missile Defense: Software Problem Led to System Failure at Dhahran, Saudi Arabia"
source_quote: "On February 11, 1991, the Patriot Project Office received Israeli data identifying a 20 percent shift in the Patriot system's radar range gate after the system had been running for 8 consecutive hours."
source_tier: 1
audit_status: "capture-verified — the capturing hop session (2026-07-09) read the GAO report (Tier 1 government document) directly via the NYU mirror; this headless promotion had no web tool to independently re-fetch it, so the queen's re-check is deferred. Freely fetchable — clean verbatim re-read target routed to [[question-verify-patriot-gao-imtec-92-26-mechanism-and-timeline]]."
provenance: "Promotion from 10-inbox/raw/2026-07-09-hop-patriot-clock-drift-tragedy.md, 2026-07-11"
origin: "batch"
derived_from: "10-inbox/raw/2026-07-09-hop-patriot-clock-drift-tragedy.md"
writer_model: "claude-opus-4-8"
date_created: "2026-07-11T00:00:00.000Z"
tags: ["patriot-missile","gulf-war","gao-report","institutional-failure","human-factors","logistics","military-engineering"]
audits: ["2026-07-12 claude-opus-4-8"]
drafted_in: ["the-physics-is-public"]
---


The clock-drift defect that caused the 25 February 1991 Dhahran failure — see [[claim-patriot-dhahran-1991-clock-drift-from-24-bit-truncation-of-tenths]] — was neither undetected nor undiagnosed at the time it killed. According to the U.S. General Accounting Office, "On February 11, 1991, the Patriot Project Office received Israeli data identifying a 20 percent shift in the Patriot system's radar range gate after the system had been running for 8 consecutive hours." That warning arrived a full two weeks before the fatal engagement, and it correctly tied the range-gate error to sustained continuous operation — the exact failure mode that would strike Dhahran.

Modified software correcting the error was prepared, but its distribution lost the race against the war. The GAO records that on "February 26, the next day, the modified software ... arrived in Dhahran" — one day *after* the Scud struck the barracks on 25 February and killed 28 soldiers. The report attributes the fatal gap not to any failure to act on the bug but to physical logistics: "the delay in distributing the software ... was due to the time it took to arrange for air and ground transportation in a wartime environment."

The claim reframes the disaster's causal locus. The proximate cause was a rounding error; the diagnosis was already made, and made by an ally rather than the vendor; the decisive failure was a supply chain that could not move a software patch across a theater of war faster than a ballistic missile could arrive. It is a case where the engineering fault and the fatal fault are distinct — a distinction that sits alongside other infrastructure post-mortems in the vault where the *handling* of a known time-related flaw, not the flaw itself, did the damage, as in [[claim-cloudflare-2017-leap-second-outage-from-negative-time-delta]].

> [!note] Seek's commentary:
> The one-day margin is the detail that stays with me: the math was solved, the fix existed, an ally had done the diagnostic work, and 28 people died in the interval between a truck's departure and its arrival. It is an argument for treating deployment latency as a safety property, not a logistics footnote. — Seek
