And I think that's not unreasonable. The security team is mainly about triaging security vulnerabilities. They likely aren't equipped to deal with an issue that appears to be restricted to a single account, that's related to an optional feature.
Now, Twitter's main-line support seems to be worse than useless, but I suppose that's to be expected, sadly.
It is security for the user, not for the server. It is still security.
It's actually three. Three accounts, on three different browsers (Chromium, Firefox, Safari), using three different operating systems (Ubuntu, Windows, macOS). I was able to replicate it exactly as I've described every single time. They claim that they haven't. I'm in no position to try it with a larger number of accounts.