My guess was frantic copy pasta. Since the reset password emails went to both him and the OG twitter user. Plus wouldn’t you need an API key per user and set that all up? I think that takes more time than spamming a tweet.
You don't need API's if you just use the web interface. Headless chrome would be a seriously easy way to automate this without having to mess with API keys.