The relay attack (which is not what this article is about) relies on an erroneous idea in the design of keyless entry and keyless ignition systems.
Signals from an RFID device don't travel very far. So, (here's the error) if the keys can receive and respond to a signal from the car they must be very close to the car.
But signals can be relayed. Crook A stands next to your car. Crook B walks up to your front door.
Crook B is relying on the fact that most people leave their car keys on a key hook, or in a bowl, or maybe even in their outside jacket, which they leave by the door because that's convenient. You have done this.
The car is sending radio pulses. "Hey, are you my key?". Crook A has a relay transceiver, it doesn't need to understand this pulse, just relay it to Crook B. Crook B has another transceiver, and when it says "Hey, are you my key?" the key, on the far side of a locked front door, says "Yes! I'm the right key, see! 023483109" and Crook B's transceiver sends that right back to Crook A. "Yes! I'm the right key, see! 023483109" the one-time code from the key matches, the car unlocks. Crook A gets into the car and starts it. Crook B walks over and gets into the passenger seat.
In a few seconds the car will discover that the key, which was apparently right there, has somehow vanished. But for safety reasons it is unsafe to suddenly lock everything and shut off. The thieves will ensure that by the time it decides it would be safe to lock itself, it's inside a chop shop and that's too late.
So no, the attacker doesn't "have" the key, they just need to be able to stand relatively close to it.