People do this all the time, not only with Twitter keys, but DB connection strings and so on. On Stack Overflow, I edit peoples posts to remove their credentials and then let them know. Nice move on the post - I think it's good to let people know when they have a vulnerability.