I guess I am wrong...
He used my KeyUtils program which has a mode that allowed you to do a form of recovery that could be done over a VPS, which was made to help people, but instead he abused the fact that he still had access to Dannu's FTP server and recovered his key that way. That's why you should never give a shady person access to your server, and if you accidentally do, change your damn password. (Which he didn't do.)
There is a
fake key generator included. But I'd like to clarify, it is FAKE. From the modification discussion topic: (Just to clarify... They don't work. It's theoretically possible for them to work, but the chances are... 0.00000000000000008%. Sooo... Not that good.)