He didn't. The attacker helped out with a site that didn't use OpenID and doesn't salt their passwords.
And Jeff used an insecure password on both the "evil site" and his Open ID provider.
The attacker only had access to Jeff's hash because he had access to a site that Jeff used.