This is a common (and completely understandable) misunderstanding of the relevant paragraph:
"Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. ...
The FBI may use different words to describe this tool, but make no mistake: Building a version of iOS that bypasses security in this way would undeniably create a backdoor. ...
The government suggests this tool could only be used once, on one phone. But that’s simply not true. Once created, the technique could be used over and over again, on any number of devices. ..." [0]
Notice how the first sentence of the last paragraph talks about "this tool". "The tool" is the specific version of iOS that the FBI wants Apple to make that would only run on the phone that it wants to unlock.
Notice how the third sentence talks about "the technique". The change in terminology isn't accidental. "The technique" is "the act of demonstrating that Apple can create (and can be ordered to create) a backdoored version of iOS that bypasses tamper protection features of iOS".
The particular software that Apple would create can surely trivially be restricted to run on only a single iPhone. Unless there's a way to make iPhones run unsigned OS code without wiping the device, the only way that the image that Apple provides the FBI could be modified to run on a different iPhone is if someone got a hold of Apple's code signing keys. [1]
The problem to which Cook refers to is -therefore- not that there's a risk that someone might steal the image Apple provides to the FBI and use it to pwn more phones... it's that the government will do as it always does and keep coming back over and over and over again, demanding that Apple produce yet another image that unlocks yet another single phone of interest, regardless of whether or not they expect that the data on that phone will be particularly crucial to their case.
I expect that this would be disastrous for Apple's reputation. It certainly would not be good for society as a whole.
On the one hand, I can see how denying the government's request would be good for the industry and society. On the other hand, if the courts ultimately asserted that the FBI's request is legal and proper, it might spur Apple (and other similar companies) to ensure that the parts of their devices that handle device encryption and unlocking were not upgradable by any means... making generation of software to bypass features of those parts next to impossible.
OTOH, such an assertion would leave software-only privacy software (like Signal, GPG, WhatsApp, et. al.) in a really bad spot.
[0] http://www.apple.com/customer-letter/
[1] If someone gets Apple's code signing keys, many people are going to have many bad days.