you don't need to be using an iOS device for someone to use your devices authentication token to access your account. Sounds like perhaps a a vulnerability leaking oauth tokens in the iOS client?
I would assume it's just sent through the API with the iOS App's app credentials (they are open and out there). That specific set of app credentials allows the OAuth endpoint for email + password sign in through the API. Maybe some other database got hacked and the user credentials were used on twitter.
Or something to do with Twitter's iPhone integration having an issue, allowing someone to create credentials on your behalf.