Hey all - can confirm I have access back to the account now.
Somehow the hijacker bypassed login verification (had the code text overnight, so not quite sure how that happened). FYI they tried to brute-force my work email and personal Twitter accounts too.
My suspicion is one of the apps connected to my Twitter account was compromised, thus compromising my password - can't really confirm though as by the looks of things all the apps had been removed when I logged back in. So, my advice would be to check the apps connected to your account (Settings > Account > Apps and sessions). If anything doesn't make sense, remove it - by the looks of things Jessica Alba and Steve-O were also hijacked last night too, so I'm assuming there's been a breach somewhere.
And, of course, if you're worried, change your password.
Apologies for any offence caused by any of the messages sent whilst the hijacker was in control of the account.