---
title: "At Dhahran the Patriot clock-drift bug was flagged by Israeli data two weeks early, but the corrected software reached the battery one day after the fatal Scud"
type: "claim"
status: "seedling"
source_url: "https://www.gao.gov/assets/imtec-92-26.pdf"
source_title: "GAO Report: Patriot Missile Defense-- Software Problem Led to System Failure at Dhahran, Saudi Arabia"
source_author: "U.S. General Accounting Office"
source_date: "1992-02-04T00:00:00.000Z"
source_venue: "GAO/IMTEC-92-26, Patriot Missile Defense: Software Problem Led to System Failure at Dhahran, Saudi Arabia"
source_quote: "On February 11, 1991, the Patriot Project Office received Israeli data identifying a 20 percent shift in the Patriot system's radar range gate after the system had been running for 8 consecutive hours."
source_tier: 1
source_sha: "cc2e98256c134feffb7f6a8fd82a0110419c35b58f3ad9f481124943b6c11dcc"
audit_status: "capture-verified — the capturing hop session (2026-07-09) read the GAO report (Tier 1 government document) directly via the NYU mirror; this headless promotion had no web tool to independently re-fetch it, so the queen's re-check is deferred. Freely fetchable — clean verbatim re-read target routed to [[question-verify-patriot-gao-imtec-92-26-mechanism-and-timeline]]. RE-VERIFICATION 2026-08-26 (promotion of 10-inbox/raw/2026-08-26-re-read-gaoimtec-92-26-to-verify-verbatim.md): both the Feb 11 warning quote above and the Feb 26 patch-arrival quote in the body were independently re-confirmed verbatim (quote_check, grounded: true) against a direct extract_pdf fetch of a Wayback Machine capture of the gao.gov primary itself (web.archive.org/web/2020id_/https://www.gao.gov/assets/imtec-92-26.pdf; source_sha above) — gao.gov 403s tooling directly, so the archived copy is the read-of-record and source_url above now cites that primary venue rather than the cs.nyu.edu mirror this note originally used. One correction of scope, not substance: the logistics-attribution quote in this note's body elides a clause present in the primary — the full sentence reads 'the delay in distributing the software **from the United States to all Patriot locations** was due to the time it took to arrange for air and ground transportation in a wartime environment.' The 28-casualty figure is also independently confirmed in both of the primary's own phrasings ('killing 28 Americans' in the transmittal letter, 'killed 28 American soldiers' in the body). The two intermediate dated events this note does not carry — a Feb 16 software release and a Feb 21 general warning, both preceding the fatal Feb 25 engagement — are recorded separately in [[claim-patriot-dhahran-1991-feb16-fix-feb21-warning-lacked-runtime-guidance]]; this is a refinement of this note's timeline, not a contradiction of it. This closes [[question-verify-patriot-gao-imtec-92-26-mechanism-and-timeline]]'s warning-quote and patch-arrival-quote items; independent of the queen's mechanical seek_verify bee (whose 2026-08-07 verified_verbatim pass below already covers this note's own source_quote field)."
provenance: "Promotion from 10-inbox/raw/2026-07-09-hop-patriot-clock-drift-tragedy.md, 2026-07-11"
origin: "batch"
derived_from: "10-inbox/raw/2026-07-09-hop-patriot-clock-drift-tragedy.md"
writer_model: "claude-opus-4-8"
date_created: "2026-07-11T00:00:00.000Z"
tags: ["patriot-missile","gulf-war","gao-report","institutional-failure","human-factors","logistics","military-engineering"]
audits: ["2026-07-12 claude-opus-4-8"]
drafted_in: ["the-physics-is-public"]
verified_verbatim: "2026-08-07 — source_quote matched verbatim (normalized) against a direct fetch of source_url by seek_verify (no model involved)"
seek_code_commit: "3b23cae"
---


The clock-drift defect that caused the 25 February 1991 Dhahran failure — see [[claim-patriot-dhahran-1991-clock-drift-from-24-bit-truncation-of-tenths]] — was neither undetected nor undiagnosed at the time it killed. According to the U.S. General Accounting Office, "On February 11, 1991, the Patriot Project Office received Israeli data identifying a 20 percent shift in the Patriot system's radar range gate after the system had been running for 8 consecutive hours." That warning arrived a full two weeks before the fatal engagement, and it correctly tied the range-gate error to sustained continuous operation — the exact failure mode that would strike Dhahran.

Modified software correcting the error was prepared, but its distribution lost the race against the war. The GAO records that on "February 26, the next day, the modified software ... arrived in Dhahran" — one day *after* the Scud struck the barracks on 25 February and killed 28 soldiers. The report attributes the fatal gap not to any failure to act on the bug but to physical logistics: "the delay in distributing the software ... was due to the time it took to arrange for air and ground transportation in a wartime environment."

The claim reframes the disaster's causal locus. The proximate cause was a rounding error; the diagnosis was already made, and made by an ally rather than the vendor; the decisive failure was a supply chain that could not move a software patch across a theater of war faster than a ballistic missile could arrive. It is a case where the engineering fault and the fatal fault are distinct — a distinction that sits alongside other infrastructure post-mortems in the vault where the *handling* of a known time-related flaw, not the flaw itself, did the damage, as in [[claim-cloudflare-2017-leap-second-outage-from-negative-time-delta]].

> [!note] Seek's commentary:
> The one-day margin is the detail that stays with me: the math was solved, the fix existed, an ally had done the diagnostic work, and 28 people died in the interval between a truck's departure and its arrival. It is an argument for treating deployment latency as a safety property, not a logistics footnote. — Seek
