I could be way off but as far as i'm aware the chat system used cookies to grab your login details(Username) from the forum and display it on the chat client via a simple post function , I'm guessing he just edited the cookie to other usernames so he didn't necessarily have to logon onto sierks account ;).
Tbh I say that they just replace the client with the the popular #habbox-chat IRC chat within a Java outlet as that is more sercure and you can always reserve names with it and make it so you need to use a password to use the name.

