Earlier quoted context omitted.
Couldn't another app use these tokens and take advantage of lax api limits ?
Yes. And that's the point of the disclosure.
Of course, you still have to log in as a user, and Twitter could blacklist accounts that use this key on non-Twitter apps, which are going to have a lot of 'tells' and a specific signature in patterns of how they use the API.
(Twitter could even take advantage of that by hiding a code in a usage pattern, kind of like the POW who blinked in Morse code when he was put on TV)