I find it hard to believe this was a Social Engineering based attack. Elon Musk’s account was accessed multiple times after their tweets being deleted and it seemed to last forever, account by account being taken over.
Also, the ability to impersonate people (not just celebrities) should require at least manual approvals. Not sure why this ability even exists.
The original speculation (that it was an API vulnerability) is actually easier to stomach.