Nuclear reactors are complex beasts. Very complex. For example, here's [1] the webpage with NRC's safety evaluation documents for NuScale's small modular reactors. Dozens of documents, totaling more than one thousand pages. In many cases, there are years of work behind a single paragraph. Here's [2] an example where the NRC replies to some concerns raised by some advisory committee regarding some potential scenarios where the reactor may turn unsafe because of some boron technicality:
>>4.Operator recovery actions raise the possibility of an influx of deborated water into the core, which may result in recriticality, return to power, and the potential for core damage. Staff Response: In the staff’s SER for Chapter 19, dated July 17, 2020, (ADAMS Accession No. ML20196L734), the staff identified two post-event recovery scenarios that could pose a challenge to reactivity control. The first scenario is recovery from a non-LOCA extended decay heat removal system (DHRS) cooling condition which can occur following initiating events such as general transients and losses of off-site power. The second scenario is recovery from a LOCA ECCS cooling condition which can occur following initiating events such as breaks in the primary coolant lines. The staff notes that either action to inject would likely be governed by plant-specific procedures; however, such procedures are not required at the design certification stage and have not been developed. The staff evaluated the potential core damage risk for the two scenarios. For reasons discussed in the SER which are supported by two papers developed by the Office of Nuclear Regulatory Research (RES) (ADAMS Accession Nos. ML20191A069 and ML20205L317), the staff concludes that enough margin exists such that these recovery scenarios are unlikely to lead to core damage based on the physical effects of fluid mixing, reactivity feedback mechanisms, and associated time constants. Based on the SER and the two RES papers, the staff found that there is reasonable assurance that there are no known significant risk contributors that are unaccounted for and that the identified risk insights are acceptable to support the uses of probabilistic risk assessment (PRA) at the design stage.
My point is: there are plenty of corner cases, maybe thousands, and in many of these corner cases the outcome can be either a nuclear boom, or at least a Chernobyl or Fukushima scenario. They are low probability but high danger scenarios, so you need to spend a lot of time (and research money) to either rule out each corner case, or to develop foolproof mitigants.
When people say that this or that reactor design is inherently safe, they are talking about first order effects. When the NRC goes into all the details, things always get a bit more complex.
Edit: by the way, nuclear fission reactors can be supercritical (all current commercial ones), or subcritical (those need an external source of neutrons or protons, such as an accelerator). Only subcritical reactors [3] can be truly pasively safe. There are concepts of subcritical reactors that use Thorium as a fuel, but that's not what China is trying here. China is trying a classical Thorium reactor, where Thorium is used to breed fissile Uranium (not the classical U-235, but rather the isotopes U-232 and U-233), and that Uranium in turn proceeds to undergo the (supercritical) fission chain reaction.
[1] https://www.nrc.gov/docs/ML2002/ML20023A318.html
[2] https://www.nrc.gov/docs/ML2023/ML20231A598.pdf
[3] https://en.wikipedia.org/wiki/Subcritical_reactor