Hi ford543! Yes, that's correct. It's the same as the HashCash model, where user put in a stake as proof of work. This is our security control, to prevent spam reports from abusive users. Once the report is proven true (via the consensus process), the deposit will be returned back to the user and he will be eligible to the bounty reward that will be distributed in relation to that reported scam.
This is a good control measure. We know that scammers will try to make the most of every opportunity that they can find. What happens to sites that will be proven to be scam?