The reactor behind the game
Meltdown looks like an arcade game, but the buttons drive a genuine CANDU reactor model — the same physics a real station operator manages. This page explains what is actually happening inside that reactor, and points to where you meet each idea while you play. No textbook required.
Why CANDU is different
Every reactor runs on the same trick: a uranium nucleus splits, throws out two or three neutrons, and those neutrons go on to split more uranium. The catch is that freshly-born neutrons are moving far too fast to split U-235 reliably. You have to slow them down first, using a moderator. What you slow them down with is the decision that defines the whole machine.
CANDU — CANada Deuterium Uranium — uses heavy water (D₂O) as its moderator. Heavy water is ordinary water in which the hydrogen is deuterium, a hydrogen atom carrying an extra neutron. Deuterium slows neutrons down almost as well as ordinary hydrogen, but it barely absorbs them. Ordinary "light" water is a thirstier absorber, so light-water reactors have to make up for the lost neutrons by enriching their fuel to 3–5 % U-235.
Because a heavy-water moderator wastes so few neutrons, CANDU can run on natural uranium — about 0.7 % U-235, straight out of the ground with no enrichment plant. The neutron economy is that tight. That single choice cascades into everything else on this page: the long, gentle timescales, the need to refuel constantly, and a quirk that makes fast shutdown non-negotiable.
Controlling the chain reaction
Operators talk about the health of the chain reaction as reactivity: how far the reactor is from perfectly self-sustaining. Perfectly balanced — each fission causing exactly one more — is critical, and reactivity is zero. Reactivity is measured in milli-k (mk), where 1 mk is one part in a thousand. A few mk is a big deal; the whole game is played in single-digit mk.
Here is the part that makes a reactor operable at all. If reactors depended only on the neutrons released the instant a nucleus splits — the prompt neutrons — power would double faster than any human or machine could react. But a small fraction of neutrons arrive late, spat out seconds to minutes afterward by the decay of certain fission fragments. These delayed neutrons are only about 0.5–0.7 % of the total, yet they set the pace of the entire reactor. As long as you keep reactivity below that delayed fraction (the prompt-criticality margin, roughly 6 mk here), power changes at the leisurely pace of the delayed neutrons, not the prompt ones. Cross it, and the reactor no longer needs the delayed neutrons to grow — that is the line you never want to approach.
This core: βeff ≈ 5.6 mk (equilibrium fuel), prompt neutron lifetime ≈ 0.9 ms (long, thanks to heavy water). CANDU gets a bonus delayed source too: gamma rays from the core knock neutrons out of the D₂O itself (photoneutrons), so a CANDU never fully loses its delayed neutrons even after shutdown.
Fourteen buckets of water
A CANDU core is big — physically larger than the distance a neutron travels in its life. That makes it loosely coupled: one side of the core can climb in power while the other side sinks, with the total barely moving. So you cannot control a CANDU with one master knob. You need to control power everywhere at once and shape it region by region.
The tool for both jobs is the liquid zone control system: fourteen compartments of ordinary light water spread through the core. Light water absorbs neutrons, remember — so each compartment is a dial-able neutron sponge. Fill a compartment and you soak up neutrons and lower power there; drain it and power rises. Move all fourteen together for bulk power control; move them against each other to fight a tilt and flatten the flux. In this model the fourteen compartments are worth about 7 mk in total, roughly half a mk each — small, fast, and always working.
Why fourteen? Because the loosely-coupled core wants to slosh power from side to side (you will see exactly why in the xenon section), and you need enough independent handles to catch that slosh before it grows. Fourteen zones, arranged as two halves of seven, is enough to see and correct a tilt.
Refuelling on the run
Natural-uranium fuel does not last long — there is only so much U-235 in it — so a CANDU is refuelled constantly, a few channels at a time, day in and day out. A light-water reactor shuts down for weeks every 12–24 months to swap fuel. A CANDU almost never shuts down for fuel at all, because it refuels at full power.
It manages this because the fuel sits in hundreds of individual horizontal pressure tubes — fuel channels — rather than one big vessel. A pair of robotic fuelling machines clamp onto both ends of a channel while the reactor runs, push fresh fuel bundles in one end, and catch the spent ones out the other. Fresh fuel is slightly more reactive than the fuel it replaces, so each refuelling nudges reactivity up locally — which is exactly why refuelling is a reactivity tool, not just housekeeping.
The reactor poisons itself
Splitting uranium makes more than heat and neutrons; it makes a zoo of new isotopes, and one of them fights back. Xenon-135 is a fission product with a monstrous appetite for neutrons — it is one of the strongest neutron absorbers known. At steady full power the reactor burns xenon off as fast as it is made, and it settles at a roughly constant drag (about −28 mk in this core).
The trouble comes when you drop the power — or trip. Xenon is still being created by the decay of iodine-135 left over from when the reactor was hot, but with the flux gone there are no longer enough neutrons to burn it away. So xenon piles up for hours, peaking roughly 9–11 hours after a shutdown before finally decaying. During that peak the reactor is buried under far more negative reactivity than all your rods can overcome. It is poisoned out: you physically cannot restart it, and you simply wait — sometimes most of a day — for the xenon to decay.
There is a narrow escape window right after a trip, before the xenon peak builds, when you still have enough reactivity in hand to power back up and burn the xenon off. Miss it and the door closes. And because the core is loosely coupled, xenon does something sneakier still: a small tilt starves one region of flux, so xenon builds there while it burns off elsewhere, deepening the tilt — a slow, self-feeding xenon spatial oscillation that can swing back and forth over many hours. Left uncontrolled it grows. That is the real reason the fourteen zones exist.
Rods that add power
The zones handle the fine, everyday trimming. For bigger, deliberate reactivity there are solid rods hanging in the core. CANDU's are worth knowing because they are used backwards from what people expect.
Adjuster rods
Around 21 adjuster rods that live normally inside the core. Their day job is flattening the flux so the whole core makes power evenly. Their emergency job is being a reactivity reserve: because they are already in, withdrawing them adds a big chunk of positive reactivity — enough to help override a building xenon load after a power drop. In this model the adjusters are worth about 16 mk on the way out.
Mechanical control absorbers
A pair of MCAs that normally sit out of the core, ready to drive in fast when the reactor control system needs to shed power quickly — for example on a load rejection. They are the RRS's fast brake, sitting between the gentle zones and the emergency shutdown rods.
Stopping it now
CANDU's neutron economy buys a lot, but it comes with a famous string attached: a positive coolant void coefficient. If the heavy-water coolant in the fuel channels boils or drains away, the reactor briefly gets more reactive, not less — in this model losing the coolant is worth about +10 mk, and it happens in a heartbeat. A reactor that can add power to its own accident must be able to shut itself down faster than the accident develops, and it must be able to do so in two completely independent ways so that no single failure can leave it running.
SDS1 — the shutoff rods
Shutdown System 1 is a bank of neutron-absorbing rods held above the core by clutches. Trip it and the clutches let go: the rods drop into the core under gravity, spring-assisted, and the chain reaction collapses in a couple of seconds. This is the fast, routine trip.
SDS2 — the poison injection
Shutdown System 2 is entirely separate: high-pressure helium injects gadolinium nitrate, a fierce neutron poison, straight into the heavy-water moderator. It floods the core with negative reactivity (worth hundreds of mk) in about a second. Different principle, different hardware, no shared parts with SDS1.
From core to city
All of that reactivity control exists to make one thing: heat, steadily, on demand. Pressurised heavy-water coolant (a separate loop from the moderator) is pumped through the fuel channels, picks up the fission heat, and carries it to the steam generators — the boilers. There the heavy water gives its heat to an ordinary light-water loop, which flashes to steam, spins the turbine-generator, and lights the grid. The boilers are also the reactor's heat sink: even a tripped reactor keeps making decay heat, so if the boilers ever run dry the fuel can still overheat.
The Reactor Regulating System (RRS) is always matching reactor power to what the turbine and grid are pulling. When demand falls sharply it does not just trim — it commands a setback (a controlled ramp down) or, for a sudden loss of the grid, a fast stepback that drops power in seconds by driving the MCAs in, so the reactor does not overpressure with nowhere to send its steam.
Operate the real model
This is not a mock-up. The panel below is driven by assets/candu-core.js — the same reference core the game runs — with 14-zone coupled point kinetics solved implicitly each step, delayed-neutron and photoneutron precursors, iodine/xenon per zone, RRS bulk and spatial control, setback/stepback, a lumped heat-transport and secondary side, and SDS1/SDS2 trip logic with ECC and containment. Pick a scenario, then operate it yourself.
PLANT table — enough to make the reactor act like a reactor. The heat transport and secondary side are lumped into one loop, one boiler pressure and one pressuriser; containment is a single volume. It is not safety-analysis grade, it carries no station-specific data, and every quantity is a public representative value or a stated modelling choice — never a real plant's setpoint.
Does it check out?
The reference core is put through a scripted regression run — the same scenarios you can load above — and it reproduces the behaviours described on this page. The whole run takes about two seconds of wall-clock time.
Holds exactly
100.00 %FP, zones at 50 %, generator 915 MW, zero drift over 10 min with photoneutron precursors included in βeff.
No trip
Peak 100.1 %FP; the zones absorb the whole insertion (average level 50 → 64 %), no coarse device moves.
Spatial control works
One channel refuelled (+0.3 mk) → 5 % tilt; the affected compartment fills to 77 % while the other thirteen sit near 53 %.
Divergent xenon oscillation
Same perturbation, no spatial term: the tilt grows from 1 % to 16 % over 20 h and keeps growing — a divergent xenon spatial oscillation. This is the reason the 14 liquid zones exist.
SDS1 catches it
Zones draining with RRS off → power rises; SDS1 trips on high neutron power at ~1.9 min.
Stepback to 60 %
MCA drop to 56 %, re-clutched with MCAs 26 % in, holding 60 % from 3 min; the MCAs then withdraw as xenon builds. Return to 100 % clean, zones ending ~84 %.
Full safety sequence
Trip, void and depressurisation; RB pressure held at +7 kPa(g) by the PRVs; ECC high-pressure injection at ~3.5 min; inventory restored.
Poison-out
Peak −125 mk at 10.3 h; −12 mk relative at 30 min; post-trip growth ≈0.45 mk/min; poison-override window ≈40 min.
Critical at ~9 min
SDS1 reset, bank A out, bank B out with 5 rate holds; 60 %FP at ~17 min. The window is open.
Poisoned out
Adjusters fully out, zones empty, still ~−5 mk. Correct physics: the window closed.
Reactivity in milli-k (mk); power as a fraction of full power (%FP). All values are representative public CANDU data, not station-specific.