Why would Twitter voluntarily run that sort of query to satisfy a subpoena?
Whether it's difficult and risky for the average user depends on the threat model. "Twitter doesn't directly have my name, address, or phone number sitting in their database next to my account" is easy. Other things are more difficult.
The only thing that falls apart is the IP address identification, which is only a very small signal for identifying an internet user. X/Twitter undoubtedly has more identity information than just an IP address.
That said I don't know how much browser fingerprinting Twitter might be doing and if fingerprints from other services might be possible to crossreference. Much higher risk is probably visiting other sites both with and without the VPN using the same browser without thinking about it and thus leaking your fingerprint or even account cookies that way. Or if you don't run a filter then visiting a site without the VPN that embeds Twitter tracking assets would leak to them directly.